Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.29%—Symphony-mobile G100 Firmware14/11/201917/6/2026
The Symphony G100 Android device with a build fingerprint of Symphony/G100/G100:8.1.0/O11019/1530618779:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an…
ModificadaMedia (6.1)0.82%—B3log Symphony10/10/201917/6/2026
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
ModificadaMedia (5.4)1.0%—Simplysymphony Plugnedit26/9/201917/6/2026
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount, or plugneditcontent parameters.
ModificadaMedia (6.5)0.86%—Simplysymphony Plugnedit26/9/201917/6/2026
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters.
ModificadaCrítica (9.8)1.8%—Symphonyextensions Rich Text Formatter5/9/201917/6/2026
The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.
ModificadaMedia (4.8)0.53%—B3log Symphony20/6/201917/6/2026
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote attacks. Any Web script or HTML can be inserted by an admin-authenticated user via a crafted web…
ModificadaMedia (6.1)0.83%—Qasymphony Qtest Manager2/4/201917/6/2026
qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter.
ModificadaMedia (6.1)0.80%—B3log Symphony25/2/201917/6/2026
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
ModificadaMedia (6.5)1.2%—IBM Platform SymphonyIBM Specturm Symphony11/10/201817/6/2026
IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force ID: 146343.
ModificadaMedia (5.4)0.66%—IBM Spectrum Symphony11/10/201817/6/2026
IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 146341.
ModificadaMedia (5.4)0.71%—IBM Platform SymphonyIBM Spectrum Symphony28/9/201817/6/2026
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL…
ModificadaAlta (7.1)1.9%—IBM Platform SymphonyIBM Spectrum Symphony28/9/201817/6/2026
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 146189.
ModificadaMedia (6.5)1.3%—IBM Platform SymphonyIBM Spectrum Symphony28/8/201817/6/2026
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could allow an authenticated attacker to obtain highly sensitive information. IBM X-Force ID: 146340.
ModificadaAlta (8.8)2.4%—IBM Platform SymphonyIBM Spectrum Symphony1/8/201817/6/2026
IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary commands due to improper handling of user supplied input. IBM X-Force ID: 143622.
ModificadaMedia (6.1)0.82%—Getsymphony Symphony7/6/201817/6/2026
content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.
ModificadaCrítica (9.8)2.1%—B3log Symphony27/4/201817/6/2026
b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.
ModificadaMedia (6.1)0.74%—Symphony Project Symphony27/11/201717/6/2026
b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a private letter with a certain /article URI, and a second private letter with a modified title.
ModificadaMedia (6.1)0.82%—Symphony Project Symphony18/11/201717/6/2026
b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL value to /settings/avatar, related to processor/AdminProcessor.java, processor/ArticleProcessor.java, processor/UserProcessor.java, service/ArticleQueryService.java, service/AvatarQueryService.java,…
ModificadaMedia (5.4)0.48%—B3log Symphony15/11/201717/6/2026
b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP address in /admin/user/userid.
ModificadaMedia (6.1)0.76%—Getsymphony Symphony10/5/201717/6/2026
Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.
ModificadaAlta (8.8)4.4%—Getsymphony Symphony11/4/201717/6/2026
Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor.
ModificadaMedia (6.1)0.76%—Getsymphony Symphony27/3/201717/6/2026
Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.
ModificadaMedia (6.1)1.2%—Getsymphony Symphony20/1/201717/6/2026
Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter.
ModificadaMedia (5.3)2.5%—Getsymphony Symphony20/1/201717/6/2026
Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in the existing-folder and new-folder parameters.
ModificadaAlta (7.5)10%—Getsymphony Symphony30/6/201617/6/2026
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.