Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.6% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Event CenterCisco Webex Meeting Center+2 | 26/11/2019 | 17/6/2026 | A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URLs. An attacker could… | |
| Modificada | Media (6.5) | 1.6% | — | Jenkins Support Core | 21/11/2019 | 17/6/2026 | A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary files on the Jenkins master. | |
| Modificada | Media (6.5) | 0.71% | — | Jenkins Support Core | 21/11/2019 | 17/6/2026 | A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete support bundles. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Media (4.3) | 1.3% | — | Atlassian Troubleshooting AND SupportAtlassian BambooAtlassian BitbucketAtlassian Confluence+4 | 8/11/2019 | 17/6/2026 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the… | |
| Modificada | Media (5.4) | 0.78% | — | Solaplugins Sola Support Tickets | 20/9/2019 | 17/6/2026 | The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS. | |
| Modificada | Crítica (9.8) | 18% | — | Haxx CurlFedoraproject FedoraOpensuse LeapNetapp Cloud Backup+13 | 16/9/2019 | 17/6/2026 | Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. | |
| Modificada | Crítica (9.8) | 7.5% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Steelstore+8 | 16/9/2019 | 17/6/2026 | Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. | |
| Modificada | Media (6.1) | 1.1% | — | Supportflow Project Supportflow | 16/9/2019 | 17/6/2026 | The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt. | |
| Modificada | Media (6.1) | 1.0% | — | Supportflow Project Supportflow | 16/9/2019 | 17/6/2026 | The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title. | |
| Modificada | Media (6.1) | 0.91% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. | |
| Modificada | Crítica (9.8) | 2.0% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. | |
| Modificada | Media (6.1) | 0.91% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. | |
| Modificada | Crítica (9.1) | 2.5% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. | |
| Modificada | Crítica (9.8) | 2.2% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. | |
| Modificada | Media (5.3) | 1.3% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure. | |
| Modificada | Crítica (9.8) | 1.8% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection. | |
| Modificada | Alta (7.5) | 1.4% | — | Getawesomesupport Awesome Support | 20/8/2019 | 17/6/2026 | The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies. | |
| Modificada | Media (6.1) | 0.91% | — | Getawesomesupport Awesome Support | 20/8/2019 | 17/6/2026 | The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages. | |
| Modificada | Alta (7.8) | 0.35% | — | Intel Driver & Support Assistant | 19/8/2019 | 17/6/2026 | Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.30% | — | Intel Driver & Support Assistant | 19/8/2019 | 17/6/2026 | Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle iSupport component of Oracle E-Business Suite (subcomponent: Service Requests). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport.… | |
| Modificada | Alta (7.8) | 0.69% | — | Haxx CurlOracle Enterprise Manager OPS CenterOracle Http ServerOracle Mysql Server+5 | 2/7/2019 | 17/6/2026 | A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants. | |
| Modificada | Alta (7.8) | 2.2% | — | Pc-doctor ToolboxDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 25/6/2019 | 17/6/2026 | PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element. | |
| Modificada | Alta (7.8) | 1.6% | 💥 PoC | HP Support Assistant | 25/6/2019 | 17/6/2026 | HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328. |