Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.69% | — | Victor Zsviot CameraAI | 19/5/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Victor Zsviot Camera 8.26.31. This affects an unknown part of the component MQTT Packet Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Aplazada | Media (4.3) | 0.32% | — | Uriahs Victor Location Picker AT Checkout FOR WoocommerceAI | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9. | |
| Modificada | Crítica (9.8) | 0.84% | — | Victor CMS Project Victor CMS | 8/5/2023 | 17/6/2026 | SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request. | |
| Modificada | Alta (8.8) | 1.5% | — | Victor CMS Project Victor CMS | 16/6/2022 | 17/6/2026 | Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php. | |
| Modificada | Alta (7.5) | 1.6% | — | Victor CMS Project Victor CMS | 28/4/2022 | 17/6/2026 | SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php. | |
| Modificada | Alta (8.8) | 20% | — | Victor CMS Project Victor CMS | 21/4/2022 | 17/6/2026 | Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin. | |
| Modificada | Crítica (9.8) | 1.5% | — | Victor CMS Project Victor CMS | 4/3/2022 | 17/6/2026 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Alta (8.8) | 1.3% | — | Victor CMS Project Victor CMS | 3/2/2022 | 17/6/2026 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Victor CMS Project Victor CMS | 31/1/2022 | 17/6/2026 | Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters. | |
| Modificada | Alta (7.5) | 1.4% | — | Victor CMS Project Victor CMS | 31/1/2022 | 17/6/2026 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter. | |
| Modificada | Crítica (9.8) | 1.9% | — | Victor CMS Project Victor CMS | 23/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php. | |
| Modificada | Crítica (9.8) | 1.9% | — | Victor CMS Project Victor CMS | 2/12/2020 | 17/6/2026 | The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page. | |
| Modificada | Media (5.3) | 0.53% | — | Johnsoncontrols C-cure WEBJohnsoncontrols Victor WEB | 19/11/2020 | 17/6/2026 | A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under… | |
| Modificada | Alta (7.5) | 1.2% | — | Victor CMS Project Victor CMS | 27/10/2020 | 17/6/2026 | A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database. | |
| Modificada | Alta (8.1) | 1.1% | — | Johnsoncontrols Victor WEB ClientTyco C-cure WEB Client | 8/10/2020 | 17/6/2026 | A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service attack. | |
| Modificada | Media (6.1) | 2.1% | — | Victor CMS Project Victor CMS | 7/7/2020 | 17/6/2026 | Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field. | |
| Modificada | Media (6.1) | 0.87% | — | Victorcms Project Victorcms | 22/6/2020 | 17/6/2026 | Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter. | |
| Modificada | Media (6.5) | 0.99% | — | Tyco Victor Video Management SystemJohnsoncontrols C-cure 9000 Firmware | 21/5/2020 | 17/6/2026 | During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation. | |
| Modificada | Media (4.8) | 0.53% | — | Victor CMS Project Victor CMS | 10/9/2018 | 17/6/2026 | An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu. | |
| Modificada | Media (6.1) | 0.65% | — | Victor CMS Project Victor CMS | 21/8/2018 | 17/6/2026 | An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "Leave a Comment" screen. | |
| Modificada | Baja (3.3) | 0.21% | — | Huawei Victoria-al00 Firmware | 31/7/2018 | 17/6/2026 | Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an interface does not verify authorization correctly, attackers can exploit an application with the authorization of phone state to obtain user location additionally. | |
| Modificada | Media (5.5) | 0.55% | — | Huawei Vicky-al00aHuawei Victoria-al00aHuawei Warsaw-al00 | 22/11/2017 | 17/6/2026 | The Bastet of some Huawei mobile phones with software earlier than Vicky-AL00AC00B167 versions, earlier than Victoria-AL00AC00B167 versions, earlier than Warsaw-AL00C00B191 versions has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing… | |
| Modificada | Media (4.6) | 0.22% | — | Huawei Maya-l02 FirmwareHuawei Vky-l09 FirmwareHuawei Vky-l29 FirmwareHuawei Vicky-al00a Firmware+2 | 22/11/2017 | 17/6/2026 | Maya-L02,VKY-L09,VTR-L29,Vicky-AL00A,Victoria-AL00A,Warsaw-AL00 smart phones with software of earlier than Maya-L02C636B126 versions,earlier than VKY-L29C10B151 versions,earlier than VTR-L29C10B151 versions,earlier than Vicky-AL00AC00B162 versions,earlier than Victoria-AL00AC00B167 versions,earlier than… | |
| Modificada | Alta (7.8) | 1.1% | — | Huawei Vicky-al00a FirmwareHuawei Vicky-al00c FirmwareHuawei Vicky-tl00a FirmwareHuawei Victoria-al00a Firmware+1 | 22/11/2017 | 17/6/2026 | The Madapt Driver of some Huawei smart phones with software Earlier than Vicky-AL00AC00B172 versions,Vicky-AL00CC768B122,Vicky-TL00AC01B167,Earlier than Victoria-AL00AC00B172 versions,Victoria-TL00AC00B123,Victoria-TL00AC01B167 has a use after free (UAF) vulnerability. An attacker can trick a user to install a… |