Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.56% | — | SAP Infrabox | 10/8/2021 | 17/6/2026 | Due to improper input validation in InfraBox, logs can be modified by an authenticated user. | |
| Modificada | Alta (8.1) | 0.77% | — | Abox Project Abox | 8/8/2021 | 17/6/2026 | An issue was discovered in the abox crate before 0.4.1 for Rust. It implements Send and Sync for AtomicBox<T> with no requirement for T: Send and T: Sync. | |
| Modificada | Alta (7.5) | 1.1% | — | SAP Infrabox | 9/6/2021 | 17/6/2026 | Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application. | |
| Modificada | Media (5.4) | 0.66% | — | Ideabox Powerpack Addons FOR Elementor | 5/5/2021 | 17/6/2026 | The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Alta (7.5) | 1.4% | — | Metabox Meta BOX | 9/8/2019 | 17/6/2026 | The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders. | |
| Modificada | Media (6.5) | 1.7% | 💥 Exploit | Metabox Meta BOX | 9/8/2019 | 17/6/2026 | The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter. | |
| Modificada | Alta (7.5) | 6.0% | — | Shellinabox Project Shellinabox | 21/3/2019 | 17/6/2026 | libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down. | |
| Modificada | Alta (7.5) | 1.5% | — | Zipato Zipabox Firmware | 13/8/2018 | 17/6/2026 | Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface. | |
| Modificada | Crítica (9.8) | 1.1% | — | Zipato Zipabox Firmware | 13/8/2018 | 17/6/2026 | Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extract clear text passwords and get root access on the device. | |
| Modificada | Crítica (9.8) | 2.4% | — | Zipato Zipabox Firmware | 13/8/2018 | 17/6/2026 | Insecure configuration storage in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows remote attacker perform new attack vectors and take under control device and smart home. | |
| Modificada | Media (6.1) | 1.1% | — | Geminabox Project Geminabox | 13/11/2017 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. | |
| Modificada | Alta (8.8) | 0.50% | — | Geminabox Project Geminabox | 25/9/2017 | 17/6/2026 | geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. | |
| Modificada | Media (5.4) | 0.68% | — | Geminabox Project Geminabox | 25/9/2017 | 17/6/2026 | geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. | |
| Modificada | Media (6.1) | 1.7% | — | Assist Project Assist PluginDatabox Project Databox PluginUserbox Project Userbox Plugin | 14/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.4) | 2.0% | — | Fedoraproject FedoraShellinabox Project Shellinabox | 12/1/2016 | 17/6/2026 | The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Phpoutsourcing Ideabox | 21/11/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in include.php in PHPOutsourcing IdeaBox (aka IdeBox) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the gorumDir parameter. | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Rabox Winlpd | 18/7/2006 | 16/6/2026 | Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a request to TCP port 515. | |
| Modificada | Alta (7.5) | 1.2% | — | Mediabox404 | 23/8/2005 | 16/6/2026 | SQL injection vulnerability in login_admin_mediabox404.php in mediabox404 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the User field. | |
| Modificada | Media (4.3) | 1.2% | — | PHP Arena Pabox | 3/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the News module for paBox 1.6 allows remote attackers to inject arbitrary web script or HTML via the text hidden parameter in an HTTP POST request. |