Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.66% | — | Esafenet CDG | 6/10/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is the function delCatelogs of the file /CDGServer3/document/Catelogs;logindojojs?command=DelCatelogs. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.64% | — | Esafenet CDG | 5/10/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /MultiServerBackService?path=1. The manipulation of the argument fileId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (7.6) | 0.35% | — | Esafenet CDG | 30/9/2024 | 17/6/2026 | ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface | |
| Analizada | Crítica (9.1) | 0.63% | — | Esafenet CDG | 5/9/2024 | 17/6/2026 | SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page. | |
| Modificada | Alta (7.5) | 2.1% | — | Esafenet CDG | 30/9/2019 | 17/6/2026 | CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal. | |
| Modificada | Alta (7.5) | 40% | 💥 Exploit | Esafenet Electronic Document Security Management System | 8/3/2019 | 17/6/2026 | ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request. |