Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.45% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/controller.php'… | |
| Analizada | Crítica (9.8) | 0.46% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe Paypal | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'end' in '/admin/mod_reports/printreport.php' parameter. | |
| Analizada | Media (6.1) | 0.28% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe Paypal | 6/8/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/index.php'. | |
| Analizada | Media (6.1) | 0.28% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe Paypal | 6/8/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/printreport.php'. | |
| Analizada | Media (6.1) | 0.28% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe Paypal | 6/8/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'q', 'arrival', 'departure' and 'accomodation' parameters in '/index.php'. | |
| Analizada | Alta (7.5) | 0.41% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'categ' in '/admin/mod_reports/printreport.php' parameter. | |
| Analizada | Media (5.3) | 0.45% | — | Baidu Ueditor | 1/8/2024 | 17/6/2026 | A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.45% | — | Baidu Ueditor | 1/8/2024 | 17/6/2026 | A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Modificada | Alta (7.1) | 0.15% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suite | 31/7/2024 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Modificada | Media (6.1) | 0.33% | — | Henleyedition Counterpoint | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echenley Counterpoint allows Reflected XSS.This issue affects Counterpoint: from n/a through 1.8.1. | |
| Modificada | Media (5.4) | 0.27% | — | Amplifyplugins Login Logo Editor | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AMP-MODE Login Logo Editor allows Stored XSS.This issue affects Login Logo Editor: from n/a through 1.3.3. | |
| Aplazada | Baja (3.5) | 0.28% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Opmanager PlusAIZohocorp Manageengine Opmanager MSPAIZohocorp Manageengine Opmanager Enterprise EditionAI | 17/7/2024 | 17/6/2026 | Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module. | |
| Analizada | Crítica (9.3) | 92% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Expedition | 10/7/2024 | 17/6/2026 | Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data… | |
| Aplazada | Alta (7.5) | 2.6% | 💥 Exploit | Edito CMSAI | 2/7/2024 | 17/6/2026 | Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthenticated user. The issue in versions 3.5 - 3.25 was removed in releases which dates from 10th of January 2014. Higher versions were never… | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Aplazada | Alta (7.3) | 0.21% | — | Jamf Compliance EditorAI | 27/6/2024 | 17/6/2026 | The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation. | |
| Aplazada | Media (6.8) | 0.38% | — | Spotfire Enterprise Runtime FOR R - Server EditionAISpotfire Statistics ServicesAISpotfire DesktopAISpotfireAI+1 | 27/6/2024 | 17/6/2026 | Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue… | |
| Modificada | Alta (8.2) | 0.18% | — | Dell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 FirmwareDell Alienware Aurora R13 Firmware+18 | 13/6/2024 | 17/6/2026 | Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Modificada | Alta (8.2) | 0.18% | — | Dell XPS 8960 FirmwareDell XPS 8950 FirmwareDell Inspiron 3502 FirmwareDell Inspiron 15 3521 Firmware+19 | 13/6/2024 | 17/6/2026 | Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Modificada | Alta (8.2) | 0.18% | — | Dell XPS 8960 FirmwareDell XPS 8950 FirmwareDell Inspiron 3502 FirmwareDell Inspiron 15 3521 Firmware+19 | 13/6/2024 | 17/6/2026 | Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Modificada | Media (6) | 0.15% | — | Dell XPS 8960 FirmwareDell XPS 8950 FirmwareDell Inspiron 3502 FirmwareDell Inspiron 15 3521 Firmware+19 | 13/6/2024 | 17/6/2026 | Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Modificada | Crítica (9.1) | 0.59% | — | Themehigh Checkout Field Editor FOR Woocommerce | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro) allows Functionality Misuse, File Manipulation.This issue affects Checkout Field Editor for WooCommerce (Pro): from n/a through 3.6.2. | |
| Modificada | Alta (7.6) | 0.17% | — | Dell Vostro 5625 FirmwareDell Vostro 5515 FirmwareDell Vostro 5415 FirmwareDell Vostro 3405 Firmware+36 | 7/6/2024 | 17/6/2026 | Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system. | |
| Aplazada | Media (6.3) | 0.78% | — | OtrsAIOtrs Community EditionAI | 6/6/2024 | 17/6/2026 | The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially leading to the execution of local code like Perl scripts. This issue… | |
| Aplazada | Alta (7.5) | 0.38% | — | Wp-db-table-editor WP DB Table EditorAI | 4/6/2024 | 17/6/2026 | The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to lack of a default capability requirement on the 'dbte_render' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with… |