Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

61 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.80%—Prise Adas20/9/201917/6/2026
An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected XSS in the error message.
ModificadaAlta (7.5)1.4%—Prise Adas20/9/201917/6/2026
An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form.
ModificadaMedia (6.5)1.0%—Prise Adas20/9/201917/6/2026
An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload.
ModificadaMedia (6.1)0.52%—Prise Adas20/9/201917/6/2026
An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submitting a rogue certificate.
ModificadaCrítica (9.1)2.0%—Prise Adas20/9/201917/6/2026
An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to an arbitrary file read and deletion via Directory Traversal.
ModificadaMedia (5.4)0.86%—Prise Adas20/9/201917/6/2026
An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the administration panel.
ModificadaMedia (6.1)1.2%💥 PoCPrise Adas20/9/201917/6/2026
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.
ModificadaMedia (6.1)1.0%—Prise Adas20/9/201917/6/2026
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to reflected XSS.
ModificadaMedia (5)1.3%—Adastra Trace Mode Data Center18/4/201216/6/2026
Unspecified vulnerability in AdAstrA TRACE MODE Data Center allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by the GLEG Agora SCADA+ Exploit Pack for Immunity CANVAS.
ModificadaAlta (7.5)7.8%💥 ExploitMastersfusion MF Piadas30/6/200616/6/2026
PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page parameter. NOTE: the same vector can be used for cross-site scripting, but CVE analysis suggests that this is resultant from file inclusion of HTML or script.
ModificadaAlta (7.8)2.2%—TEG Tenes Empanadas Graciela10/3/200616/6/2026
Buffer overflow in Tenes Empanadas Graciela (TEG) 0.11.1, automatically appends an _ (underscore) to the end of duplicate nicknames, which allows remote attackers to cause a denial of service (application crash) by creating multiple users with long, identical nicknames, which triggers an off-by-one error.
Orbitaley — Vulnerabilidades