Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.8%—Apache Libapreq2Fedoraproject FedoraDebian Linux25/8/202217/6/2026
A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
ModificadaAlta (7.8)0.39%—LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+1023/8/202217/6/2026
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may…
ModificadaAlta (7.8)0.39%—LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+923/8/202217/6/2026
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL…
ModificadaMedia (6.1)0.83%—Elastic Kibana6/7/202217/6/2026
A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.
ModificadaAlta (8.8)7.5%💥 ExploitAlibaba Nacos5/7/202217/6/2026
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
ModificadaCrítica (9.8)1.4%—Zibal Project Zibal24/6/202217/6/2026
The Zibal package in PyPI v1.0.0 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaMedia (5.4)0.91%—Dolibarr Erp/crm13/6/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
ModificadaCrítica (9.8)19%💥 PoCAlibaba FastjsonOracle Communications Cloud Native Core Unified Data Repository10/6/202217/6/2026
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable…
ModificadaMedia (6.1)0.71%—Dolibarr Erp/crm8/6/202217/6/2026
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
ModificadaCrítica (9.8)3.9%💥 PoCAlibabagroup One-java-agent1/5/202217/6/2026
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or…
ModificadaMedia (5.3)0.92%—Elastic Kibana21/4/202217/6/2026
A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to…
ModificadaAlta (7.5)0.98%—Dolibarr Erp/crm31/3/202217/6/2026
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
ModificadaAlta (8.8)0.93%—Dolibarr Erp/crm31/3/202217/6/2026
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
ModificadaAlta (7.8)0.39%—Hibara Attachecase31/3/202217/6/2026
Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)0.38%—Hibara Attachecase31/3/202217/6/2026
Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (6.5)1.9%—LibarchiveFedoraproject Fedora28/3/202217/6/2026
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
ModificadaAlta (7.2)2.5%💥 PoCTribalsystems Zenario14/3/202217/6/2026
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.
ModificadaMedia (4.8)0.51%—Tribalsystems Zenario14/3/202217/6/2026
Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicious files to victims and steals victim's cookie leads to account takeover. The person viewing the image of a contact can be victim of XSS.
ModificadaMedia (6.1)0.83%💥 PoCAlibaba Nacos11/3/202217/6/2026
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.
ModificadaCrítica (9.8)3.0%—LiquibaseOracle Sqlcl4/3/202217/6/2026
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
ModificadaMedia (6.1)0.77%—Elastic Kibana3/3/202217/6/2026
A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.
ModificadaMedia (4.3)0.55%—Elastic Kibana3/3/202217/6/2026
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify…
ModificadaAlta (8.8)41%—Dolibarr Erp/crm2/3/202217/6/2026
Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
ModificadaMedia (4.3)0.88%—Dolibarr Erp/crm25/2/202217/6/2026
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
ModificadaAlta (7.2)1.5%—Tribalsystems Zenario24/2/202217/6/2026
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.
Orbitaley — Vulnerabilidades