Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)33%💥 PoCDolibarr Erp/crm1/11/202317/6/2026
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
ModificadaMedia (4.8)0.46%—Dolibarr Erp/crm30/10/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.
ModificadaAlta (7.5)0.78%—Elastic Kibana26/10/202317/6/2026
An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this…
ModificadaMedia (5.4)0.66%💥 PoCTribalsystems Zenario25/10/202317/6/2026
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.
ModificadaAlta (8.8)0.59%—Wazuh-dashboardWazuh-kibana-app9/10/202317/6/2026
Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their…
ModificadaMedia (5.4)0.57%💥 PoCTribalsystems Zenario6/10/202317/6/2026
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout.
ModificadaMedia (5.4)0.59%💥 PoCTribalsystems Zenario6/10/202317/6/2026
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.
ModificadaMedia (6.1)0.44%—Dolibarr Erp/crm1/10/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.
ModificadaCrítica (9.6)1.3%—Dolibarr Erp/crm20/9/20239/7/2026
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
ModificadaAlta (8.8)1.5%—Dolibarr Erp/crm20/9/20239/7/2026
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
ModificadaAlta (7.2)32%—Dolibarr Erp/crm20/9/20239/7/2026
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
ModificadaMedia (4.8)0.44%—Tribalsystems Zenario28/8/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.
ModificadaAlta (7.5)0.80%—Alibaba Tengine22/8/202317/6/2026
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.
ModificadaAlta (8.8)1.3%—Alibabacloud Nacos Spring Project21/8/202317/6/2026
An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.
ModificadaAlta (7.5)0.94%—Fujifilm Docuprint M265 Z FirmwareFujifilm Docuprint M268 Z FirmwareFujifilm Docuprint M225 Z FirmwareFujifilm Docuprint M225 DW Firmware+21211/7/202317/6/2026
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information…
ModificadaMedia (6.5)0.60%—Fibaro Fgms-001 Firmware20/6/202317/6/2026
A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message.
ModificadaAlta (7.5)15%💥 ExploitDolibarr Erp/crm13/6/202317/6/2026
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
ModificadaAlta (8.8)82%💥 ExploitDolibarr Erp/crm29/5/202317/6/2026
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
ModificadaMedia (5.3)0.19%—Libarchive29/5/202317/6/2026
Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to…
ModificadaAlta (8.8)0.96%—Elastic Kibana4/5/202317/6/2026
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.
ModificadaAlta (8.8)0.60%—Elastic Kibana4/5/202317/6/2026
Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of…
ModificadaMedia (6.5)0.65%—Budibase6/4/202317/6/2026
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to Server-Side Request Forgery. This can lead to an attacker gaining access to a Budibase AWS secret key. Users of Budibase cloud need to take no action. Self-host users who…
ModificadaCrítica (9.8)0.60%—Atm-consulting Dolibarr Module Quicksupplierprice20/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version…
ModificadaMedia (6.1)0.52%—Elastic Kibana22/2/202317/6/2026
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
ModificadaMedia (6.5)0.89%—Decode-uri-component Project Decode-uri-componentElastic Kibana8/2/202317/6/2026
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
Orbitaley — Vulnerabilidades