Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.4% | — | Redaxo | 9/10/2018 | 17/6/2026 | There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4. | |
| Modificada | Media (6.1) | 0.83% | — | Redaxo | 9/10/2018 | 17/6/2026 | Mediamanager in REDAXO before 5.6.4 has XSS. | |
| Modificada | Media (6.1) | 0.91% | — | Redaxo | 9/10/2018 | 17/6/2026 | The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is output directly to the page. The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=[XSS] request. | |
| Modificada | Crítica (9.8) | 2.1% | — | Redaxo | 1/10/2018 | 17/6/2026 | In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.php, via the index.php?page=users/users sort parameter. Endangered was the backend and the frontend only if rex_list were used. | |
| Modificada | Media (5.4) | 0.68% | — | Redaxo | 1/10/2018 | 17/6/2026 | The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not restricted (only values are restricted). The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=&args[ substring. | |
| Modificada | Alta (8.8) | 0.62% | — | Redaxo CMS | 25/8/2018 | 17/6/2026 | An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user. | |
| Modificada | Media (4.3) | 1.2% | — | Redaxo | 13/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in include/classes/class.rex_list.inc.php in REDAXO 4.3.x and 4.4 allows remote attackers to inject arbitrary web script or HTML via the subpage parameter to index.php. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Redaxo | 6/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to (1) simple_user/pages/index.inc.php and (2) stats/pages/index.inc.php. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Redaxo | 6/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to image_resize/pages/index.inc.php. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Redaxo | 6/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the (1) REX[INCLUDE_PATH] parameter in (a) addons/import_export/pages/index.inc.php and (b) pages/community.inc.php. |