Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.59%—Liballeg Allegro3/2/202317/6/2026
Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.
ModificadaAlta (7.8)0.35%—Toshiba Storage Security Software31/1/202317/6/2026
Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module.
ModificadaCrítica (9.8)0.66%—Aibattle Project Aibattle13/1/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in Dovgalyuk AIBattle. Affected by this vulnerability is the function registerUser of the file site/procedures.php. The manipulation of the argument postLogin leads to sql injection. The identifier of the patch is…
ModificadaCrítica (9.8)0.74%—Aibattle Project Aibattle13/1/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Dovgalyuk AIBattle. Affected is the function sendComments of the file site/procedures.php. The manipulation of the argument text leads to sql injection. The name of the patch is e3aa4d0900167641d41cbccf53909229f00381c9. It is…
ModificadaMedia (6.5)0.32%—Dolibarr Project Timesheet Project Dolibarr Project Timesheet27/12/202217/6/2026
A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading to version 4.5.6.a is able to address…
ModificadaAlta (8.8)1.2%—Ibarn Project Ibarn15/12/202217/6/2026
File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to run arbitrary code via avatar upload to index.php.
ModificadaCrítica (9.8)1.2%💥 PoCTribalsystems Zenario30/11/202217/6/2026
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario30/11/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The exploit has been disclosed to the public…
ModificadaCrítica (9.8)2.4%—LibarchiveDebian LinuxFedoraproject FedoraSplunk Universal Forwarder22/11/202217/6/2026
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare…
ModificadaCrítica (9.8)4.2%—Dolibarr Erp/crm21/11/202217/6/2026
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker…
ModificadaMedia (5.4)0.49%—Elastic Kibana18/11/202217/6/2026
It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.
ModificadaMedia (6.1)0.57%—Elastic Kibana18/11/202217/6/2026
An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.
ModificadaCrítica (9.8)1.3%—Dolibarr Erp/crm17/11/202217/6/2026
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario16/11/202217/6/2026
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario16/11/202217/6/2026
Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario16/11/202217/6/2026
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles.
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario16/11/202217/6/2026
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module.
ModificadaMedia (6.1)0.43%—Tribalsystems Zenario2/11/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the…
ModificadaAlta (8.8)0.56%—Go-ibax1/11/202217/6/2026
A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.…
ModificadaAlta (8.8)30%—Go-ibax1/11/202217/6/2026
A vulnerability, which was classified as critical, was found in IBAX go-ibax. This affects an unknown part of the file /api/v2/open/rowsInfo. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (8.8)2.6%💥 ExploitGo-ibax1/11/202217/6/2026
A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.63%—Go-ibax1/11/202217/6/2026
A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated…
ModificadaAlta (8.8)0.56%—Go-ibax1/11/202217/6/2026
A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212634 is the identifier…
ModificadaCrítica (9.8)33%—Dolibarr Erp/crm12/10/202217/6/2026
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
ModificadaMedia (5.7)0.96%—Budibase16/9/202217/6/2026
Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.
Orbitaley — Vulnerabilidades