Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

81 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.36%—Palantir Apollo Autopilot27/9/202317/6/2026
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.
ModificadaMedia (5.9)0.80%—Apollographql Apollo Router5/9/202317/6/2026
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when GraphQL Subscriptions are enabled. It can be…
ModificadaAlta (7.5)0.82%—Apolloconfig Apollo20/2/202317/6/2026
Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service. Malicious hackers may access eureka…
ModificadaMedia (5.7)0.35%—Apolloconfig Apollo20/2/202317/6/2026
Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any confirmation from the Portal admin. Cookie SameSite strategy…
ModificadaMedia (6.1)0.81%—Apollotheme AP Pagebuilder31/1/20239/7/2026
A cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the show_number parameter.
ModificadaAlta (8.8)0.85%—Apollo Project Apollo14/1/202317/6/2026
A vulnerability, which was classified as critical, was found in abreen Apollo. This affects an unknown part. The manipulation of the argument file leads to path traversal. The patch is named 6206406630780bbd074aff34f4683fb764faba71. It is recommended to apply a patch to fix this issue. The associated identifier of…
ModificadaCrítica (9.8)14%💥 ExploitApollotheme AP Pagebuilder29/8/202217/6/2026
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.
ModificadaCrítica (9.8)1.5%—Apollosapp Data-connector-rock16/6/202117/6/2026
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within the app, as well as…
ModificadaMedia (5.4)0.56%—Apollo13themes Rife Elementor Extensions & Templates5/5/202117/6/2026
The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method.
ModificadaMedia (6.8)0.52%—HP Apollo 2000 FirmwareHP Apollo 4200 Gen10 FirmwareHP Apollo 4500 FirmwareHP Proliant Xl230k Gen10 Firmware+175/11/202017/6/2026
A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this…
ModificadaAlta (7)1.3%—Ctrip Apollo10/9/202017/6/2026
apollo-adminservice before version 1.7.1 does not implement access controls. If users expose apollo-adminservice to internet(which is not recommended), there are potential security issues since apollo-adminservice is designed to work in intranet and it doesn't have access control built-in. Malicious hackers may access…
ModificadaMedia (6.5)3.1%—Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+15614/11/201917/6/2026
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
ModificadaAlta (8.2)0.38%—Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+28014/11/201917/6/2026
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of…
ModificadaMedia (6.7)0.38%—Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+28014/11/201917/6/2026
Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local…
ModificadaMedia (4.3)7.3%💥 ExploitAlkacon Opencms Apollo Template27/8/201917/6/2026
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.
ModificadaMedia (6.1)2.9%💥 ExploitAlkacon Opencms Apollo Template27/8/201917/6/2026
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
ModificadaMedia (6.1)2.9%💥 ExploitAlkacon Opencms Apollo Template27/8/201917/6/2026
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
ModificadaCrítica (10)1.6%—Ctrip Apollo1/4/201917/6/2026
An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.
ModificadaMedia (6.8)0.43%—Apollotechnologiesinc Momentum Axel 720pApollotechnologiesinc Momentum Axel 720p Firmware13/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at the console.
ModificadaMedia (4.4)0.33%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. All processes run as root.
ModificadaMedia (6.7)0.38%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the root CLI. This password may be the same on all devices
ModificadaMedia (6.8)0.43%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full system compromise.
ModificadaMedia (6.8)0.45%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. Custom Firmware Upgrade is possible via an SD Card. With physical access, an attacker can upgrade the firmware in under 60 seconds by inserting an SD card containing the firmware with name 'ezviz.dav' and rebooting.
ModificadaMedia (4.4)0.35%—Apollotechnologiesinc Momentum Axel 720p Firmware12/6/201817/6/2026
An issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hijacking. An authenticated root user with CLI access is able to remotely upgrade firmware to a custom image due to lack of SSL validation by changing the nameservers in /etc/resolv.conf to the…
ModificadaCrítica (9.8)4.6%—Apache Activemq Apollo27/10/201717/6/2026
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Orbitaley — Vulnerabilidades