Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 67 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.36% | — | Presstigers Simple JOB Board | 15/5/2025 | 17/6/2026 | In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor | |
| Aplazada | Crítica (9) | 0.92% | — | Jupyter Remote Desktop ProxyAITigervncAI | 15/4/2025 | 17/6/2026 | Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the… | |
| Aplazada | Media (6.5) | 0.24% | — | Hutsixdigital TigerAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hutsixdigital Tiger allows Stored XSS.This issue affects Tiger: from n/a through 2.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Presstigers Simple OWL CarouselAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple Owl Carousel simple-owl-carousel allows DOM-Based XSS.This issue affects Simple Owl Carousel: from n/a through <= 1.1.1. | |
| Modificada | Alta (7.8) | 0.39% | — | TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux | 25/2/2025 | 29/6/2026 | A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the… | |
| Modificada | Alta (7.8) | 0.39% | — | TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux | 25/2/2025 | 29/6/2026 | A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free. | |
| Modificada | Alta (7.8) | 0.40% | — | TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux | 25/2/2025 | 29/6/2026 | An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly… | |
| Modificada | Alta (7.8) | 0.40% | — | TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux | 25/2/2025 | 29/6/2026 | An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found,… | |
| Modificada | Alta (7.8) | 0.44% | — | TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux | 25/2/2025 | 29/6/2026 | A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are… | |
| Modificada | Alta (7.8) | 0.44% | — | TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux | 25/2/2025 | 29/6/2026 | A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow. | |
| Modificada | Alta (7.8) | 0.44% | — | TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux | 25/2/2025 | 29/6/2026 | A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size. | |
| Modificada | Alta (7.8) | 0.39% | — | TigervncX.org X ServerX.org XwaylandRedhat Enterprise Linux | 25/2/2025 | 29/6/2026 | A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free. | |
| Analizada | Media (5.3) | 0.40% | — | Vtiger CRM | 24/2/2025 | 17/6/2026 | A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.1) | 0.20% | — | Master Software Solutions WP Vtiger SynchronizationAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Master Software Solutions WP VTiger Synchronization msstiger allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through <= 1.1.1. | |
| Analizada | Media (6.1) | 0.36% | — | Vtiger CRM | 10/1/2025 | 17/6/2026 | Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php. | |
| Modificada | Crítica (9.8) | 0.44% | — | Presstigers Simple JOB Board | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in PressTigers Simple Job Board simple-job-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through <= 2.10.5. | |
| Aplazada | Media (5.9) | 0.27% | — | Presstigers Simple Testimonials ShowcaseAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple Testimonials Showcase simple-testimonials-showcase allows Stored XSS.This issue affects Simple Testimonials Showcase: from n/a through <= 1.1.6. | |
| Analizada | Media (5.4) | 0.31% | — | Vtiger CRM | 14/10/2024 | 17/6/2026 | Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML. | |
| Modificada | Crítica (9.6) | 0.78% | — | Vtiger CRM | 29/8/2024 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Modificada | Crítica (9.6) | 0.73% | — | Vtiger CRM | 29/8/2024 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Modificada | Crítica (9.6) | 0.72% | — | Vtiger CRM | 29/8/2024 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Modificada | Media (6.1) | 0.32% | — | Vtiger CRM | 29/8/2024 | 5/7/2026 | An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL. | |
| Analizada | Alta (7.2) | 0.62% | — | Presstigers Simple JOB Board | 24/8/2024 | 17/6/2026 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP… | |
| Analizada | Alta (8.3) | 0.40% | — | Vtiger CRM | 16/8/2024 | 17/6/2026 | VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules. | |
| Analizada | Alta (7.2) | 0.49% | — | Vtiger CRM | 16/8/2024 | 17/6/2026 | VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module. |