Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.86% | — | Alfresco Content ServicesAlfresco Transform Services | 21/10/2021 | 17/6/2026 | An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e.,… | |
| Modificada | Alta (8.8) | 1.5% | — | Alfresco Content Services | 21/10/2021 | 17/6/2026 | An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment. | |
| Modificada | Alta (8.1) | 0.97% | — | Oracle Content Manager | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Content Item Manager). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks… | |
| Modificada | Media (5.7) | 0.42% | — | Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+6 | 18/10/2021 | 17/6/2026 | Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before… | |
| Modificada | Media (6.5) | 0.82% | — | Hitachi Content Platform Anywhere | 29/9/2021 | 17/6/2026 | Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the link and then later deletes the file or folder without deleting the link and before the link… | |
| Modificada | Media (5.4) | 0.57% | — | Ericsson Enterprise Content Management | 17/9/2021 | 17/6/2026 | In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover. | |
| Modificada | Alta (8) | 1.1% | — | Ericsson Enterprise Content Management | 17/9/2021 | 17/6/2026 | In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection. | |
| Modificada | Alta (8.8) | 1.7% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 13/9/2021 | 17/6/2026 | The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages. | |
| Modificada | Media (6.5) | 1.0% | — | IBM Content Navigator | 9/8/2021 | 17/6/2026 | IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968. | |
| Modificada | Alta (7.2) | 1.3% | — | Ays-pro Secure Copy Content Protection AND Content Locking | 2/8/2021 | 17/6/2026 | The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard | |
| Modificada | Media (6.1) | 0.84% | — | Content Management System Project Content Management System | 22/7/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter to content_management_system\admin\new_content.php | |
| Modificada | Media (6.5) | 0.80% | — | Content Copy Protection & Prevent Image Save Project Content Copy Protection & Prevent Image Save | 1/6/2021 | 17/6/2026 | The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in administrator set arbitrary XSS payloads in them. | |
| Modificada | Alta (8.8) | 1.3% | — | Wp-buy WP Content Copy Protection & NO Right Click | 14/5/2021 | 17/6/2026 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps… | |
| Modificada | Media (6.5) | 1.0% | — | Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security ApplianceCisco Ironport WEB Security Appliance | 6/5/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA), Cisco Email Security Appliance (ESA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The… | |
| Modificada | Media (6.7) | 0.27% | — | Cisco Content Security Management Appliance | 6/5/2021 | 17/6/2026 | A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, local attacker to elevate their privileges to root. This vulnerability is due to a procedural flaw in the password generation algorithm. An attacker could exploit… | |
| Modificada | Media (4.9) | 1.4% | — | Dynamic Content Elements Project Dynamic Content Elements | 28/4/2021 | 17/6/2026 | The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Content Navigator | 27/4/2021 | 17/6/2026 | IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199168. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Content Navigator | 27/4/2021 | 17/6/2026 | IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199167. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Content Navigator | 27/4/2021 | 17/6/2026 | IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196624. | |
| Modificada | Media (6.1) | 0.73% | — | Wfiltericf Wfilter Internet Content Filter | 15/4/2021 | 17/6/2026 | Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet with a malicious User-Agent header to inject a payload in its logs, where an attacker can take over the system by through its plugin-running function. | |
| Modificada | Media (4.3) | 0.21% | — | Mcafee Content Security Reporter | 15/4/2021 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway Cloud Server (MWGCS) read only user used to… | |
| Modificada | Alta (7.5) | 1.0% | — | Forcepoint Data Loss PreventionForcepoint Email SecurityForcepoint WEB Security Content Gateway | 8/4/2021 | 17/6/2026 | Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure. | |
| Modificada | Media (5.4) | 0.66% | — | Ovation Dynamic Content | 19/3/2021 | 17/6/2026 | Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter. | |
| Modificada | Media (5.4) | 0.86% | — | Opentext Content Server | 26/2/2021 | 17/6/2026 | There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 20.3. The application allows a remote attacker to introduce arbitrary JavaScript by crafting malicious form values that are later not sanitized. | |
| Modificada | Alta (8.8) | 1.7% | — | Atlassian Alfresco Enterprise Content Management | 19/2/2021 | 17/6/2026 | An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco. |