Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.0% | — | Opentext Documentum Content Server | 22/2/2017 | 17/6/2026 | OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and execute arbitrary DML or DDL… | |
| Modificada | Media (6.1) | 0.76% | — | Netresearch Contexts Wurfl | 12/2/2017 | 17/6/2026 | An issue was discovered in contexts_wurfl (for TYPO3) before 0.4.2. The vulnerability exists due to insufficient filtration of user-supplied data in the "force_ua" HTTP GET parameter passed to the "/contexts_wurfl/Library/wurfl-dbapi-1.4.4.0/check_wurfl.php" URL. An attacker could execute arbitrary HTML and script… | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Php-gettext Project Php-gettext | 7/2/2017 | 17/6/2026 | Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header. | |
| Modificada | Alta (8.6) | 2.7% | — | Cisco ASA CX Context-aware Security Software | 1/2/2017 | 17/6/2026 | A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a denial of service (DoS) condition. The vulnerability is… | |
| Analizada | Crítica (9.8) | 93% | ⚠ Explotación activa💥 Exploit | Apache AuroraApache ShiroRedhat FuseRedhat Jboss Middleware Text-only Advisories | 7/6/2016 | 17/6/2026 | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter. | |
| Modificada | Crítica (9.8) | 3.1% | — | Opentext Vertica | 20/4/2016 | 17/6/2026 | The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPort parameter, aka ZDI-CAN-3417. | |
| Modificada | Alta (8.8) | 2.5% | — | Cisco Prime Security ManagerCisco ASA CX Context-aware Security Software | 7/2/2016 | 17/6/2026 | The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842. | |
| Modificada | Alta (7.5) | 4.7% | — | Opentext Vertica | 4/11/2015 | 17/6/2026 | The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands via a crafted packet, aka ZDI-CAN-2914. | |
| Modificada | Media (4) | 1.4% | — | Cisco ASA CX Context-aware Security Software | 30/10/2015 | 17/6/2026 | The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9.3(4.1.11) allows remote authenticated users to bypass intended access restrictions and obtain sensitive user information via an unspecified HTTP request, aka Bug ID CSCuv74105. | |
| Modificada | Media (6.9) | 2.1% | — | Sonicwall Netextender | 26/8/2015 | 17/6/2026 | Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder. | |
| Modificada | Media (4.3) | 1.9% | — | Opentext Secure MFT 2013Opentext Secure MFT 2014 | 20/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in OpenText Secure MFT 2013 before 2013 R3 P6 and 2014 before 2014 R2 P2 allows remote attackers to inject arbitrary web script or HTML via the querytext parameter to userdashboard.jsp. | |
| Modificada | Alta (7.8) | 2.3% | — | Cisco ASA With Firepower ServicesCisco ASA CX Context-aware Security Software | 11/4/2015 | 17/6/2026 | The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9 allows remote attackers to cause a denial of service (device reload) by rapidly sending crafted packets to the management interface, aka Bug IDs CSCus11007 and… | |
| Modificada | Media (4.3) | 1.4% | — | Textangular | 20/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in textAngular-sanitize.js in textAngular before 1.3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the editor. | |
| Modificada | Media (5.8) | 2.2% | — | Context Project ContextFedoraproject Fedora | 15/1/2015 | 17/6/2026 | Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter. | |
| Modificada | Baja (3.5) | 2.6% | 💥 Exploit | PRO Chat Rooms Text Chat Rooms | 20/10/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php. | |
| Modificada | Media (6.5) | 1.9% | 💥 Exploit | Prochatrooms Text Chat Rooms | 20/10/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Textpattern | 10/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Textpattern CMS before 4.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to setup/index.php. | |
| Modificada | Baja (3.5) | 0.95% | — | Drupal Context Form Alteration Module | 6/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer contexts" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.29% | — | Pingshow Airetalk Text Call & More! | 15/9/2014 | 17/6/2026 | The AireTalk: Text, Call, & More! (aka com.pingshow.amper) application 2.0.73 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Go-text Text ME! Free Texting & Call | 9/9/2014 | 17/6/2026 | The Text Me! Free Texting & Call (aka com.textmeinc.textme) application 2.5.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Your-text-manager Project Your-text-manager | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in settings/pwsettings.php in the Your Text Manager plugin 0.3.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the ytmpw parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Ajaydsouza Contextual Related Posts | 2/6/2014 | 17/6/2026 | SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 1.1% | — | Ajaydsouza Contextual Related Posts | 2/6/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via unspecified vectors. | |
| Modificada | Media (6.4) | 1.2% | — | Opentext Exceed Ondemand | 19/5/2014 | 17/6/2026 | OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network. | |
| Modificada | Media (6.8) | 0.63% | — | Opentext Exceed Ondemand | 19/5/2014 | 17/6/2026 | The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses. |