Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Palantir Apollo Autopilot | 27/9/2023 | 17/6/2026 | In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction. | |
| Modificada | Media (5.9) | 0.80% | — | Apollographql Apollo Router | 5/9/2023 | 17/6/2026 | The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when GraphQL Subscriptions are enabled. It can be… | |
| Modificada | Alta (7.5) | 0.82% | — | Apolloconfig Apollo | 20/2/2023 | 17/6/2026 | Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service. Malicious hackers may access eureka… | |
| Modificada | Media (5.7) | 0.35% | — | Apolloconfig Apollo | 20/2/2023 | 17/6/2026 | Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any confirmation from the Portal admin. Cookie SameSite strategy… | |
| Modificada | Media (6.1) | 0.81% | — | Apollotheme AP Pagebuilder | 31/1/2023 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the show_number parameter. | |
| Modificada | Alta (8.8) | 0.85% | — | Apollo Project Apollo | 14/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in abreen Apollo. This affects an unknown part. The manipulation of the argument file leads to path traversal. The patch is named 6206406630780bbd074aff34f4683fb764faba71. It is recommended to apply a patch to fix this issue. The associated identifier of… | |
| Modificada | Crítica (9.8) | 14% | 💥 Exploit | Apollotheme AP Pagebuilder | 29/8/2022 | 17/6/2026 | A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data. | |
| Modificada | Crítica (9.8) | 1.5% | — | Apollosapp Data-connector-rock | 16/6/2021 | 17/6/2026 | Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within the app, as well as… | |
| Modificada | Media (5.4) | 0.56% | — | Apollo13themes Rife Elementor Extensions & Templates | 5/5/2021 | 17/6/2026 | The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Media (6.8) | 0.52% | — | HP Apollo 2000 FirmwareHP Apollo 4200 Gen10 FirmwareHP Apollo 4500 FirmwareHP Proliant Xl230k Gen10 Firmware+17 | 5/11/2020 | 17/6/2026 | A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this… | |
| Modificada | Alta (7) | 1.3% | — | Ctrip Apollo | 10/9/2020 | 17/6/2026 | apollo-adminservice before version 1.7.1 does not implement access controls. If users expose apollo-adminservice to internet(which is not recommended), there are potential security issues since apollo-adminservice is designed to work in intranet and it doesn't have access control built-in. Malicious hackers may access… | |
| Modificada | Media (6.5) | 3.1% | — | Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+156 | 14/11/2019 | 17/6/2026 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. | |
| Modificada | Alta (8.2) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of… | |
| Modificada | Media (6.7) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local… | |
| Modificada | Media (4.3) | 7.3% | 💥 Exploit | Alkacon Opencms Apollo Template | 27/8/2019 | 17/6/2026 | In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Alkacon Opencms Apollo Template | 27/8/2019 | 17/6/2026 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Alkacon Opencms Apollo Template | 27/8/2019 | 17/6/2026 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. | |
| Modificada | Crítica (10) | 1.6% | — | Ctrip Apollo | 1/4/2019 | 17/6/2026 | An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled. | |
| Modificada | Media (6.8) | 0.43% | — | Apollotechnologiesinc Momentum Axel 720pApollotechnologiesinc Momentum Axel 720p Firmware | 13/6/2018 | 17/6/2026 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at the console. | |
| Modificada | Media (4.4) | 0.33% | — | Apollotechnologiesinc Momentum Axel 720p Firmware | 12/6/2018 | 17/6/2026 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. All processes run as root. | |
| Modificada | Media (6.7) | 0.38% | — | Apollotechnologiesinc Momentum Axel 720p Firmware | 12/6/2018 | 17/6/2026 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the root CLI. This password may be the same on all devices | |
| Modificada | Media (6.8) | 0.43% | — | Apollotechnologiesinc Momentum Axel 720p Firmware | 12/6/2018 | 17/6/2026 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full system compromise. | |
| Modificada | Media (6.8) | 0.45% | — | Apollotechnologiesinc Momentum Axel 720p Firmware | 12/6/2018 | 17/6/2026 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. Custom Firmware Upgrade is possible via an SD Card. With physical access, an attacker can upgrade the firmware in under 60 seconds by inserting an SD card containing the firmware with name 'ezviz.dav' and rebooting. | |
| Modificada | Media (4.4) | 0.35% | — | Apollotechnologiesinc Momentum Axel 720p Firmware | 12/6/2018 | 17/6/2026 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hijacking. An authenticated root user with CLI access is able to remotely upgrade firmware to a custom image due to lack of SSL validation by changing the nameservers in /etc/resolv.conf to the… | |
| Modificada | Crítica (9.8) | 4.6% | — | Apache Activemq Apollo | 27/10/2017 | 17/6/2026 | XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages. |