Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.29% | — | Symphony-mobile G100 Firmware | 14/11/2019 | 17/6/2026 | The Symphony G100 Android device with a build fingerprint of Symphony/G100/G100:8.1.0/O11019/1530618779:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an… | |
| Modificada | Media (6.1) | 0.82% | — | B3log Symphony | 10/10/2019 | 17/6/2026 | b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header. | |
| Modificada | Media (5.4) | 1.0% | — | Simplysymphony Plugnedit | 26/9/2019 | 17/6/2026 | The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount, or plugneditcontent parameters. | |
| Modificada | Media (6.5) | 0.86% | — | Simplysymphony Plugnedit | 26/9/2019 | 17/6/2026 | The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters. | |
| Modificada | Crítica (9.8) | 1.8% | — | Symphonyextensions Rich Text Formatter | 5/9/2019 | 17/6/2026 | The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php. | |
| Modificada | Media (4.8) | 0.53% | — | B3log Symphony | 20/6/2019 | 17/6/2026 | In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote attacks. Any Web script or HTML can be inserted by an admin-authenticated user via a crafted web… | |
| Modificada | Media (6.1) | 0.83% | — | Qasymphony Qtest Manager | 2/4/2019 | 17/6/2026 | qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter. | |
| Modificada | Media (6.1) | 0.80% | — | B3log Symphony | 25/2/2019 | 17/6/2026 | An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Platform SymphonyIBM Specturm Symphony | 11/10/2018 | 17/6/2026 | IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force ID: 146343. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Spectrum Symphony | 11/10/2018 | 17/6/2026 | IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 146341. | |
| Modificada | Media (5.4) | 0.71% | — | IBM Platform SymphonyIBM Spectrum Symphony | 28/9/2018 | 17/6/2026 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL… | |
| Modificada | Alta (7.1) | 1.9% | — | IBM Platform SymphonyIBM Spectrum Symphony | 28/9/2018 | 17/6/2026 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 146189. | |
| Modificada | Media (6.5) | 1.3% | — | IBM Platform SymphonyIBM Spectrum Symphony | 28/8/2018 | 17/6/2026 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could allow an authenticated attacker to obtain highly sensitive information. IBM X-Force ID: 146340. | |
| Modificada | Alta (8.8) | 2.4% | — | IBM Platform SymphonyIBM Spectrum Symphony | 1/8/2018 | 17/6/2026 | IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary commands due to improper handling of user supplied input. IBM X-Force ID: 143622. | |
| Modificada | Media (6.1) | 0.82% | — | Getsymphony Symphony | 7/6/2018 | 17/6/2026 | content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page. | |
| Modificada | Crítica (9.8) | 2.1% | — | B3log Symphony | 27/4/2018 | 17/6/2026 | b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI. | |
| Modificada | Media (6.1) | 0.74% | — | Symphony Project Symphony | 27/11/2017 | 17/6/2026 | b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a private letter with a certain /article URI, and a second private letter with a modified title. | |
| Modificada | Media (6.1) | 0.82% | — | Symphony Project Symphony | 18/11/2017 | 17/6/2026 | b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL value to /settings/avatar, related to processor/AdminProcessor.java, processor/ArticleProcessor.java, processor/UserProcessor.java, service/ArticleQueryService.java, service/AvatarQueryService.java,… | |
| Modificada | Media (5.4) | 0.48% | — | B3log Symphony | 15/11/2017 | 17/6/2026 | b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP address in /admin/user/userid. | |
| Modificada | Media (6.1) | 0.76% | — | Getsymphony Symphony | 10/5/2017 | 17/6/2026 | Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php. | |
| Modificada | Alta (8.8) | 4.4% | — | Getsymphony Symphony | 11/4/2017 | 17/6/2026 | Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor. | |
| Modificada | Media (6.1) | 0.76% | — | Getsymphony Symphony | 27/3/2017 | 17/6/2026 | Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field. | |
| Modificada | Media (6.1) | 1.2% | — | Getsymphony Symphony | 20/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter. | |
| Modificada | Media (5.3) | 2.5% | — | Getsymphony Symphony | 20/1/2017 | 17/6/2026 | Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in the existing-folder and new-folder parameters. | |
| Modificada | Alta (7.5) | 10% | — | Getsymphony Symphony | 30/6/2016 | 17/6/2026 | Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter. |