Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.
ModificadaCrítica (10)1.9%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
ModificadaAlta (8.8)0.51%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass…
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos/courier/login.html auth_params CRLF attack vector.
ModificadaCrítica (9.8)1.4%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
ModificadaCrítica (9.8)1.2%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF vulnerability in settings_global_text_edit.php allowing ?display=x%0Dnewline attacks.
ModificadaMedia (6.1)1.2%💥 PoCAccellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL…
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.
ModificadaCrítica (9.8)24%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.
ModificadaMedia (4.3)2.4%—Accellion Kiteworks Appliance26/8/201617/6/2026
Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote attackers to read files via a crafted URI.
ModificadaMedia (6.1)0.90%—Accellion Kiteworks Appliance26/8/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in oauth_callback.php on Accellion Kiteworks appliances before kw2016.03.00 allow remote attackers to inject arbitrary web script or HTML via the (1) code, (2) error, or (3) error_description parameter.
ModificadaAlta (7.8)0.38%—Accellion Kiteworks Appliance26/8/201617/6/2026
Accellion Kiteworks appliances before kw2016.03.00 use setuid-root permissions for /opt/bin/cli, which allows local users to gain privileges via unspecified vectors.
ModificadaAlta (7.8)0.47%—Accellion File Transfer Appliance7/5/201617/6/2026
The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows local users to add an SSH key to an arbitrary group, and consequently gain privileges, via unspecified vectors.
ModificadaAlta (8.8)5.4%—Accellion File Transfer Appliance7/5/201617/6/2026
The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote authenticated users to execute arbitrary commands by leveraging the YUM_CLIENT restricted-user role.
ModificadaCrítica (9.8)1.6%—Accellion File Transfer Appliance7/5/201617/6/2026
SQL injection vulnerability in home/seos/courier/security_key2.api on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote attackers to execute arbitrary SQL commands via the client_id parameter.
ModificadaMedia (6.1)0.94%—Accellion File Transfer Appliance7/5/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) getimageajax.php, (2) move_partition_frame.html, or (3) wmInfo.html.
ModificadaAlta (7.2)0.82%💥 ExploitAccellion Secure File Transfer Appliance19/2/201016/6/2026
Accellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the --file_move action in /usr/local/bin/admin.pl, or a hard link attack…
ModificadaMedia (4.3)1.1%—Accellion Secure File Transfer Appliance19/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit logs.
ModificadaAlta (9)1.7%—Accellion Secure File Transfer Appliance19/2/201016/6/2026
Static code injection vulnerability in the administrative web interface in Accellion Secure File Transfer Appliance allows remote authenticated administrators to inject arbitrary shell commands by appending them to a request to update the SNMP public community string.
ModificadaAlta (7.8)2.8%💥 ExploitAccellion Secure File Transfer Appliance19/2/201016/6/2026
Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
ModificadaAlta (9)2.4%—Accellion Secure File Transfer Appliance19/2/201016/6/2026
Accellion Secure File Transfer Appliance before 8_0_105 allows remote authenticated administrators to bypass the restricted shell and execute arbitrary commands via shell metacharacters to the ping command, as demonstrated by modifying the cli program.
ModificadaAlta (7.8)6.7%💥 ExploitAccellion Secure File Transfer Appliance19/8/200916/6/2026
courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.
Orbitaley — Vulnerabilidades