Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)3.3%—Adobe Consulting Services Commons2/2/202117/6/2026
ACS Commons version 4.9.2 (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in version-compare and page-compare due to invalid JCR characters that are not handled correctly. An attacker could potentially exploit this vulnerability to inject malicious JavaScript content into vulnerable…
ModificadaAlta (7.5)1.2%—Nconsulting Nc-cms11/2/201917/6/2026
lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters.
ModificadaCrítica (9.8)2.1%—Nconsulting Nc-cms31/10/201817/6/2026
nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI.
ModificadaMedia (6.1)0.80%—Nconsulting Nc-cms15/10/201817/6/2026
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as demonstrated by a value beginning with home_content and containing a crafted SRC attribute of an IMG element.
ModificadaMedia (4.8)0.62%—Nconsulting Nc-cms14/10/201817/6/2026
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HTML Source Editor. NOTE: the vendor disputes this because the form requires administrator privileges, and entering JavaScript is supported functionality
ModificadaCrítica (9.8)3.5%—Brookinsconsulting Collected Information Export27/4/201817/6/2026
Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data.
ModificadaMedia (5)1.3%—Longwaveconsulting Ubercart Securetrading Payment Method Module31/10/201216/6/2026
The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors.
ModificadaBaja (2.1)0.94%—Tag1consulting Support Timer20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Support Timer module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "track time spent" permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (2.1)1.0%—Tag1consulting Support20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)0.87%—Hashmarkconsulting Controlpanel25/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.3%—Boesch It-consulting Progsys27/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.7%💥 ExploitBoesch It-consulting Simpnews26/10/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are…
ModificadaAlta (7.5)2.5%💥 ExploitBoesch It-consulting Progsys23/9/200616/6/2026
PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter.
ModificadaMedia (5)2.2%—Tamarack Consulting Tamarack Mmsd29/7/200616/6/2026
Tamarack MMSd before 7.992 allows remote attackers to cause a denial of service (crash) via malformed RFC1006 (OSI over TCP/IP) packets.
ModificadaAlta (10)3.6%—Himpfen Consulting PHP Simplenews19/3/200616/6/2026
admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie.
ModificadaMedia (5)2.9%💥 ExploitCurtis Specialty Consulting Iispop31/12/200216/6/2026
Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 port (TCP port 110).
ModificadaAlta (7.5)4.6%—Peaceworks Computer Consulting Phormation2/10/200116/6/2026
Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.
ModificadaAlta (7.5)3.9%💥 ExploitHassan Consulting Shopping Cart8/9/200116/6/2026
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.
ModificadaMedia (5)8.1%💥 ExploitHassan Consulting Shopping Cart19/12/200023/9/2026
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.
ModificadaAlta (7.5)2.0%—Baron Consulting Group Websitetool1/2/200016/6/2026
The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
Orbitaley — Vulnerabilidades