Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 67 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.36%—Presstigers Simple JOB Board15/5/202517/6/2026
In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
AplazadaCrítica (9)0.92%—Jupyter Remote Desktop ProxyAITigervncAI15/4/202517/6/2026
Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the…
AplazadaMedia (6.5)0.24%—Hutsixdigital TigerAI4/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hutsixdigital Tiger allows Stored XSS.This issue affects Tiger: from n/a through 2.0.
AplazadaMedia (6.5)0.26%—Presstigers Simple OWL CarouselAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple Owl Carousel simple-owl-carousel allows DOM-Based XSS.This issue affects Simple Owl Carousel: from n/a through <= 1.1.1.
ModificadaAlta (7.8)0.39%—TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux25/2/202529/6/2026
A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the…
ModificadaAlta (7.8)0.39%—TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux25/2/202529/6/2026
A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.
ModificadaAlta (7.8)0.40%—TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux25/2/202529/6/2026
An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly…
ModificadaAlta (7.8)0.40%—TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux25/2/202529/6/2026
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found,…
ModificadaAlta (7.8)0.44%—TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux25/2/202529/6/2026
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are…
ModificadaAlta (7.8)0.44%—TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux25/2/202529/6/2026
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.
ModificadaAlta (7.8)0.44%—TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux25/2/202529/6/2026
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.
ModificadaAlta (7.8)0.39%—TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux25/2/202529/6/2026
A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.
AnalizadaMedia (5.3)0.40%—Vtiger CRM24/2/202517/6/2026
A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the…
AplazadaAlta (7.1)0.20%—Master Software Solutions WP Vtiger SynchronizationAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Master Software Solutions WP VTiger Synchronization msstiger allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through <= 1.1.1.
AnalizadaMedia (6.1)0.36%—Vtiger CRM10/1/202517/6/2026
Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.
ModificadaCrítica (9.8)0.44%—Presstigers Simple JOB Board2/1/202517/6/2026
Missing Authorization vulnerability in PressTigers Simple Job Board simple-job-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through <= 2.10.5.
AplazadaMedia (5.9)0.27%—Presstigers Simple Testimonials ShowcaseAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple Testimonials Showcase simple-testimonials-showcase allows Stored XSS.This issue affects Simple Testimonials Showcase: from n/a through <= 1.1.6.
AnalizadaMedia (5.4)0.31%—Vtiger CRM14/10/202417/6/2026
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.
ModificadaCrítica (9.6)0.78%—Vtiger CRM29/8/20245/7/2026
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
ModificadaCrítica (9.6)0.73%—Vtiger CRM29/8/20245/7/2026
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
ModificadaCrítica (9.6)0.72%—Vtiger CRM29/8/20245/7/2026
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
ModificadaMedia (6.1)0.32%—Vtiger CRM29/8/20245/7/2026
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
AnalizadaAlta (7.2)0.62%—Presstigers Simple JOB Board24/8/202417/6/2026
The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP…
AnalizadaAlta (8.3)0.40%—Vtiger CRM16/8/202417/6/2026
VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.
AnalizadaAlta (7.2)0.49%—Vtiger CRM16/8/202417/6/2026
VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.