Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.0%—Dolibarr Erp/crm23/2/202217/6/2026
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
ModificadaMedia (5.4)0.53%—Elastic Kibana11/2/202217/6/2026
An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users
ModificadaMedia (4.3)0.91%—Dolibarr Erp/crm31/1/202217/6/2026
Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.
ModificadaCrítica (9.8)2.0%—Dolibarr Erp/crm14/1/202217/6/2026
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
ModificadaMedia (4.3)0.85%—Dolibarr Erp/crm10/1/202217/6/2026
Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.
ModificadaMedia (6.5)0.53%—Silabs 500 Series FirmwareAeotec Zw090-aFibaro Fgwpb-111Zooz Zen20+210/1/202217/6/2026
Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via…
ModificadaMedia (5.4)0.74%—Dolibarr Erp/crm2/1/202217/6/2026
admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.
ModificadaMedia (6.5)0.37%—Iball Wrd12en Firmware30/12/202117/6/2026
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses.
ModificadaMedia (5.4)0.95%—Dolibarr15/12/202117/6/2026
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.
ModificadaBaja (2.7)0.46%—Elastic Kibana18/11/202117/6/2026
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited…
ModificadaMedia (4.3)0.72%—Elastic Kibana18/11/202117/6/2026
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks to Dominic Couture for finding this…
ModificadaCrítica (9.8)3.9%—Dolibarr Erp/crm10/11/202117/6/2026
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
ModificadaMedia (6.1)79%—Dolibarr Erp/crm10/11/202117/6/2026
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
ModificadaAlta (7.5)1.5%—Alibaba Druid3/11/202117/6/2026
In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.
ModificadaMedia (5.5)0.22%—IBM I2 Ibase27/10/202117/6/2026
IBM i2 iBase 8.9.13 and 9.0.0 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 206213.
ModificadaMedia (6.5)0.89%—Libav23/8/202117/6/2026
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
ModificadaMedia (6.5)0.88%—Libav23/8/202117/6/2026
In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
ModificadaMedia (6.5)0.89%—Libav23/8/202117/6/2026
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
ModificadaAlta (8.8)1.1%—Dolibarr17/8/202117/6/2026
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for a forgotten password.
ModificadaAlta (7.2)0.94%—DolibarrDolibarr Erp/crm17/8/202117/6/2026
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets…
ModificadaCrítica (9)0.89%—Dolibarr15/8/202117/6/2026
In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. These scripts are executed in a victim’s browser when they open the page…
ModificadaMedia (4.3)0.70%—Dolibarr9/8/202117/6/2026
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.
ModificadaMedia (6.5)0.30%—IBM I2 Ibase26/7/202117/6/2026
IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL search order hijacking flaw. By using a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 184984.
ModificadaMedia (6.5)2.8%—LibarchiveFedoraproject FedoraApple IpadosApple Iphone OS+320/7/202117/6/2026
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
ModificadaAlta (7.8)1.1%—Libass Project LibassFedoraproject Fedora20/7/202117/6/2026
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
Orbitaley — Vulnerabilidades