Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.59% | — | Liballeg Allegro | 3/2/2023 | 17/6/2026 | Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon. | |
| Modificada | Alta (7.8) | 0.35% | — | Toshiba Storage Security Software | 31/1/2023 | 17/6/2026 | Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module. | |
| Modificada | Crítica (9.8) | 0.66% | — | Aibattle Project Aibattle | 13/1/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in Dovgalyuk AIBattle. Affected by this vulnerability is the function registerUser of the file site/procedures.php. The manipulation of the argument postLogin leads to sql injection. The identifier of the patch is… | |
| Modificada | Crítica (9.8) | 0.74% | — | Aibattle Project Aibattle | 13/1/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Dovgalyuk AIBattle. Affected is the function sendComments of the file site/procedures.php. The manipulation of the argument text leads to sql injection. The name of the patch is e3aa4d0900167641d41cbccf53909229f00381c9. It is… | |
| Modificada | Media (6.5) | 0.32% | — | Dolibarr Project Timesheet Project Dolibarr Project Timesheet | 27/12/2022 | 17/6/2026 | A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading to version 4.5.6.a is able to address… | |
| Modificada | Alta (8.8) | 1.2% | — | Ibarn Project Ibarn | 15/12/2022 | 17/6/2026 | File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to run arbitrary code via avatar upload to index.php. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Tribalsystems Zenario | 30/11/2022 | 17/6/2026 | Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE). | |
| Modificada | Media (5.4) | 0.47% | — | Tribalsystems Zenario | 30/11/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 2.4% | — | LibarchiveDebian LinuxFedoraproject FedoraSplunk Universal Forwarder | 22/11/2022 | 17/6/2026 | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare… | |
| Modificada | Crítica (9.8) | 4.2% | — | Dolibarr Erp/crm | 21/11/2022 | 17/6/2026 | SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker… | |
| Modificada | Media (5.4) | 0.49% | — | Elastic Kibana | 18/11/2022 | 17/6/2026 | It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user. | |
| Modificada | Media (6.1) | 0.57% | — | Elastic Kibana | 18/11/2022 | 17/6/2026 | An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dolibarr Erp/crm | 17/11/2022 | 17/6/2026 | Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API. | |
| Modificada | Media (5.4) | 0.47% | — | Tribalsystems Zenario | 16/11/2022 | 17/6/2026 | Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts. | |
| Modificada | Media (5.4) | 0.47% | — | Tribalsystems Zenario | 16/11/2022 | 17/6/2026 | Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile. | |
| Modificada | Media (5.4) | 0.47% | — | Tribalsystems Zenario | 16/11/2022 | 17/6/2026 | Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles. | |
| Modificada | Media (5.4) | 0.47% | — | Tribalsystems Zenario | 16/11/2022 | 17/6/2026 | Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module. | |
| Modificada | Media (6.1) | 0.43% | — | Tribalsystems Zenario | 2/11/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the… | |
| Modificada | Alta (8.8) | 0.56% | — | Go-ibax | 1/11/2022 | 17/6/2026 | A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (8.8) | 30% | — | Go-ibax | 1/11/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in IBAX go-ibax. This affects an unknown part of the file /api/v2/open/rowsInfo. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (8.8) | 2.6% | 💥 Exploit | Go-ibax | 1/11/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.63% | — | Go-ibax | 1/11/2022 | 17/6/2026 | A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated… | |
| Modificada | Alta (8.8) | 0.56% | — | Go-ibax | 1/11/2022 | 17/6/2026 | A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212634 is the identifier… | |
| Modificada | Crítica (9.8) | 33% | — | Dolibarr Erp/crm | 12/10/2022 | 17/6/2026 | Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval. | |
| Modificada | Media (5.7) | 0.96% | — | Budibase | 16/9/2022 | 17/6/2026 | Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20. |