Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.2%💥 ExploitThephpfactory Social Factory28/9/201817/6/2026
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
ModificadaCrítica (9.8)3.3%💥 ExploitThephpfactory Swap Factory28/9/201817/6/2026
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
ModificadaCrítica (9.8)3.2%💥 ExploitThephpfactory Collection Factory28/9/201817/6/2026
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
ModificadaCrítica (9.8)3.2%💥 ExploitThephpfactory Jobs Factory28/9/201817/6/2026
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
ModificadaCrítica (9.8)3.3%💥 ExploitThephpfactory Article Factory Manager28/9/201817/6/2026
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
ModificadaCrítica (9.8)3.3%💥 ExploitThephpfactory Raffle Factory28/9/201817/6/2026
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
ModificadaCrítica (9.8)3.3%💥 ExploitThephpfactory Penny Auction Factory28/9/201817/6/2026
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
ModificadaCrítica (9.8)3.2%💥 ExploitThephpfactory Reverse Auction Factory28/9/201817/6/2026
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
ModificadaAlta (8.8)0.76%—Jfrog Artifactory13/7/201817/6/2026
JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user. This attack appear to be exploitable via The victim must run maliciously crafted flash component. This…
ModificadaAlta (7.2)2.8%—Jfrog Artifactory9/7/201817/6/2026
JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability in The "Import Repository from Zip" feature, available through the Admin menu -> Import & Export -> Repositories, triggers a vulnerable UI REST endpoint (/ui/artifactimport/upload) that can result…
ModificadaAlta (7.5)1.1%—Cardfactory Project Cardfactory9/7/201817/6/2026
The mintToken function of a smart contract implementation for CardFactory, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.8)2.8%💥 ExploitRockwellautomation Rslinx ClassicRockwellautomation Factorytalk Linx Gateway7/6/201817/6/2026
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation.
ModificadaAlta (7.8)0.70%—Rockwellautomation Factorytalk Activation11/5/201817/6/2026
Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable. This may allow an authorized, but not privileged local user to execute arbitrary code with elevated privileges…
ModificadaCrítica (9.8)26%💥 ExploitJfrog Artifactory1/5/201817/6/2026
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
ModificadaAlta (7.5)4.2%—Rockwellautomation Factorytalk Alarms AND Events23/12/201717/6/2026
An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can send a specially crafted set of packets packet to Port 403/TCP (the history archiver…
ModificadaMedia (6.1)0.95%—Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+420/12/201717/6/2026
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,…
ModificadaMedia (5.3)0.34%—Azeotech Daqfactory9/9/201717/6/2026
An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An uncontrolled search path element vulnerability has been identified, which may execute malicious DLL files that have been placed within the search path.
ModificadaAlta (7.1)0.32%—Azeotech Daqfactory9/9/201717/6/2026
An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones.
ModificadaMedia (5.3)2.1%—Tinfoilsecurity Devise-two-factor6/9/201717/6/2026
Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successfully validated one-time password (aka OTP), which allows remote or physically proximate attackers with a target user's login credentials to log in as said user by obtaining the OTP through performing a…
ModificadaCrítica (9.8)1.6%—Pcfreetime Format Factory3/8/201717/6/2026
Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll.
ModificadaAlta (8.6)0.77%—Factorio26/7/201717/6/2026
A sandbox escape in the Lua interface in Wube Factorio before 0.15.31 allows remote game servers or user-assisted attackers to execute arbitrary C code by including and loading a C library.
ModificadaMedia (6.1)1.5%—Dfactory Responsive Lightbox7/7/201717/6/2026
Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.99%—SAP Successfactors15/6/201717/6/2026
Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web script or HTML via the file upload functionality.
ModificadaCrítica (9.8)3.9%—Jfrog Artifactory9/12/201617/6/2026
JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
ModificadaAlta (7.3)8.2%—Rockwellautomation Factorytalk Energrymetrix28/7/201617/6/2026
Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.