Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 4.6% | 💥 Exploit | Tribalsystems Zenario | 16/4/2021 | 17/6/2026 | SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module. | |
| Modificada | Media (4.8) | 1.1% | — | Tribalsystems Zenario | 15/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "cID" parameter when creating a new HTML component. | |
| Modificada | Media (4.9) | 1.3% | — | Tribalsystems Zenario | 15/4/2021 | 17/6/2026 | SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive database information by injecting SQL commands into the "cID" parameter when creating a new HTML component. | |
| Modificada | Alta (8.8) | 0.82% | — | Tribalsystems Zenario | 19/10/2018 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent URI. | |
| Modificada | Alta (8.8) | 0.93% | — | Tribalsystems Zenario | 22/1/2018 | 17/6/2026 | Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Categories - Edit` module. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Zenas Paobacheca Guestbook | 30/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php. | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Zenas Paolink | 25/9/2009 | 16/6/2026 | login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Zenas Paoliber | 25/9/2009 | 16/6/2026 | login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | |
| Modificada | Crítica (9.8) | 5.0% | 💥 Exploit | Zenas Pao-bacheca Guestbook | 25/9/2009 | 16/6/2026 | login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Zenas Paolink | 23/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. |