Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

56 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.66%—Esafenet CDG6/10/202417/6/2026
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is the function delCatelogs of the file /CDGServer3/document/Catelogs;logindojojs?command=DelCatelogs. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has…
AnalizadaMedia (5.3)0.64%—Esafenet CDG5/10/202417/6/2026
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /MultiServerBackService?path=1. The manipulation of the argument fileId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public…
AnalizadaAlta (7.6)0.35%—Esafenet CDG30/9/202417/6/2026
ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface
AnalizadaCrítica (9.1)0.63%—Esafenet CDG5/9/202417/6/2026
SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.
ModificadaAlta (7.5)2.1%—Esafenet CDG30/9/201917/6/2026
CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.
ModificadaAlta (7.5)40%💥 ExploitEsafenet Electronic Document Security Management System8/3/201917/6/2026
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
Orbitaley — Vulnerabilidades