Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.80% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected XSS in the error message. | |
| Modificada | Alta (7.5) | 1.4% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form. | |
| Modificada | Media (6.5) | 1.0% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload. | |
| Modificada | Media (6.1) | 0.52% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submitting a rogue certificate. | |
| Modificada | Crítica (9.1) | 2.0% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to an arbitrary file read and deletion via Directory Traversal. | |
| Modificada | Media (5.4) | 0.86% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the administration panel. | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie. | |
| Modificada | Media (6.1) | 1.0% | — | Prise Adas | 20/9/2019 | 17/6/2026 | An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to reflected XSS. | |
| Modificada | Media (5) | 1.3% | — | Adastra Trace Mode Data Center | 18/4/2012 | 16/6/2026 | Unspecified vulnerability in AdAstrA TRACE MODE Data Center allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by the GLEG Agora SCADA+ Exploit Pack for Immunity CANVAS. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Mastersfusion MF Piadas | 30/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page parameter. NOTE: the same vector can be used for cross-site scripting, but CVE analysis suggests that this is resultant from file inclusion of HTML or script. | |
| Modificada | Alta (7.8) | 2.2% | — | TEG Tenes Empanadas Graciela | 10/3/2006 | 16/6/2026 | Buffer overflow in Tenes Empanadas Graciela (TEG) 0.11.1, automatically appends an _ (underscore) to the end of duplicate nicknames, which allows remote attackers to cause a denial of service (application crash) by creating multiple users with long, identical nicknames, which triggers an off-by-one error. |