Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.32%—Uriahs Victor Location Picker AT Checkout FOR WoocommerceAI26/3/202417/6/2026
Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9.
ModificadaCrítica (9.8)0.84%—Victor CMS Project Victor CMS8/5/202317/6/2026
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
ModificadaAlta (8.8)1.5%—Victor CMS Project Victor CMS16/6/202217/6/2026
Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.
ModificadaAlta (7.5)1.6%—Victor CMS Project Victor CMS28/4/202217/6/2026
SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
ModificadaAlta (8.8)20%—Victor CMS Project Victor CMS21/4/202217/6/2026
Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.
ModificadaCrítica (9.8)1.5%—Victor CMS Project Victor CMS4/3/202217/6/2026
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
ModificadaAlta (8.8)1.3%—Victor CMS Project Victor CMS3/2/202217/6/2026
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.
ModificadaAlta (7.5)1.4%—Victor CMS Project Victor CMS31/1/202217/6/2026
Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters.
ModificadaAlta (7.5)1.4%—Victor CMS Project Victor CMS31/1/202217/6/2026
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter.
ModificadaCrítica (9.8)1.9%—Victor CMS Project Victor CMS23/7/202117/6/2026
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.
ModificadaCrítica (9.8)1.9%—Victor CMS Project Victor CMS2/12/202017/6/2026
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
ModificadaMedia (5.3)0.53%—Johnsoncontrols C-cure WEBJohnsoncontrols Victor WEB19/11/202017/6/2026
A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under…
ModificadaAlta (7.5)1.2%—Victor CMS Project Victor CMS27/10/202017/6/2026
A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database.
ModificadaAlta (8.1)1.1%—Johnsoncontrols Victor WEB ClientTyco C-cure WEB Client8/10/202017/6/2026
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service attack.
ModificadaMedia (6.1)2.1%💥 ExploitVictor CMS Project Victor CMS7/7/202017/6/2026
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
ModificadaMedia (6.1)0.87%—Victorcms Project Victorcms22/6/202017/6/2026
Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter.
ModificadaMedia (6.5)0.99%—Tyco Victor Video Management SystemJohnsoncontrols C-cure 9000 Firmware21/5/202017/6/2026
During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation.
ModificadaMedia (4.8)0.53%—Victor CMS Project Victor CMS10/9/201817/6/2026
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.
ModificadaMedia (6.1)0.65%—Victor CMS Project Victor CMS21/8/201817/6/2026
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "Leave a Comment" screen.
ModificadaBaja (3.3)0.21%—Huawei Victoria-al00 Firmware31/7/201817/6/2026
Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an interface does not verify authorization correctly, attackers can exploit an application with the authorization of phone state to obtain user location additionally.
ModificadaMedia (5.5)0.55%—Huawei Vicky-al00aHuawei Victoria-al00aHuawei Warsaw-al0022/11/201717/6/2026
The Bastet of some Huawei mobile phones with software earlier than Vicky-AL00AC00B167 versions, earlier than Victoria-AL00AC00B167 versions, earlier than Warsaw-AL00C00B191 versions has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing…
ModificadaMedia (4.6)0.22%—Huawei Maya-l02 FirmwareHuawei Vky-l09 FirmwareHuawei Vky-l29 FirmwareHuawei Vicky-al00a Firmware+222/11/201717/6/2026
Maya-L02,VKY-L09,VTR-L29,Vicky-AL00A,Victoria-AL00A,Warsaw-AL00 smart phones with software of earlier than Maya-L02C636B126 versions,earlier than VKY-L29C10B151 versions,earlier than VTR-L29C10B151 versions,earlier than Vicky-AL00AC00B162 versions,earlier than Victoria-AL00AC00B167 versions,earlier than…
ModificadaAlta (7.8)1.1%—Huawei Vicky-al00a FirmwareHuawei Vicky-al00c FirmwareHuawei Vicky-tl00a FirmwareHuawei Victoria-al00a Firmware+122/11/201717/6/2026
The Madapt Driver of some Huawei smart phones with software Earlier than Vicky-AL00AC00B172 versions,Vicky-AL00CC768B122,Vicky-TL00AC01B167,Earlier than Victoria-AL00AC00B172 versions,Victoria-TL00AC00B123,Victoria-TL00AC01B167 has a use after free (UAF) vulnerability. An attacker can trick a user to install a…
Orbitaley — Vulnerabilidades