Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.9) | 0.73% | — | Adonesevangelista Online Blood Bank Management System | 22/7/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php of the component Login. The manipulation of the argument user/pass leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.9) | 0.85% | — | Adonesevangelista Online Blood Bank Management System | 30/5/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file changepwd.php. The manipulation of the argument useremail leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.69% | — | Adonesevangelista Online Blood Bank Management System | 30/5/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file massage.php. The manipulation of the argument bid leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (7.2) | 0.80% | — | Avirtum Imagelinks | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4. | |
| Modificada | Media (5.4) | 0.47% | — | Avirtum Imagelinks | 9/1/2023 | 17/6/2026 | The ImageLinks Interactive Image Builder for WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.5) | 0.95% | — | Bridgeline Robots-txt-guard | 5/1/2023 | 17/6/2026 | A vulnerability was found in Woorank robots-txt-guard. It has been rated as problematic. Affected by this issue is the function makePathPattern of the file lib/patterns.js. The manipulation of the argument pattern leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (7.5) | 1.2% | — | Dynamicpagelist3 Project Dynamicpagelist3 | 4/10/2021 | 17/6/2026 | The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. In affected versions unsanitised input of regular expression date within the parameters of the DPL parser function, allowed for the possibility of ReDoS (Regex Denial of… | |
| Modificada | Alta (7.5) | 1.6% | — | HP Edgeline Infrastructure Management | 5/8/2021 | 17/6/2026 | A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates available to resolve the vulnerability in the… | |
| Modificada | Media (6.5) | 0.61% | — | KDE Messagelib | 2/6/2021 | 17/6/2026 | KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be… | |
| Modificada | Crítica (9.8) | 68% | 💥 Exploit | HP Edgeline Infrastructure Manager | 6/5/2021 | 17/6/2026 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged… | |
| Modificada | Crítica (9.8) | 9.6% | — | HP Edgeline Infrastructure Manager | 2/12/2020 | 17/6/2026 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of… | |
| Modificada | Alta (8.8) | 0.78% | — | Pagelines | 13/9/2019 | 17/6/2026 | The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF. | |
| Modificada | Alta (7.5) | 1.3% | — | KDE KmailKDE Messagelib | 13/6/2017 | 17/6/2026 | KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Alta (7.5) | 2.2% | — | Schneider-electric Magelis GTU Universal Panel FirmwareSchneider-electric Magelis GTO Advanced Optimum Panel FirmwareSchneider-electric Magelis Sto5 Small Panel FirmwareSchneider-electric Magelis STU Small Panel Firmware+4 | 13/2/2017 | 17/6/2026 | An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard,… | |
| Modificada | Media (5.3) | 4.3% | 💥 PoC | Schneider-electric Magelis GTU Universal Panel FirmwareSchneider-electric Magelis GTO Advanced Optimum Panel FirmwareSchneider-electric Magelis Sto5 Small Panel FirmwareSchneider-electric Magelis STU Small Panel Firmware+4 | 13/2/2017 | 17/6/2026 | An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard,… | |
| Modificada | Alta (9.3) | 4.2% | — | Sagelighteditor Sagelight | 9/8/2013 | 16/6/2026 | Integer overflow in Sagelight 4.4 and earlier allows remote attackers to execute arbitrary code via crafted width and height dimensions in a BMP file, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (10) | 2.1% | — | Schneider-electric Magelis XBT HMI | 4/4/2013 | 16/6/2026 | The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configuration data. | |
| Modificada | Media (4.3) | 1.4% | — | Dnelubin Gelinsguestbook | 23/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) message parameter. | |
| Modificada | Baja (2.1) | 0.18% | — | Pawel Jakub Dawidek Geli | 21/8/2012 | 16/6/2026 | The geli encryption provider 7 before r239184 on FreeBSD 10 uses a weak Master Key, which makes it easier for local users to defeat a cryptographic protection mechanism via a brute-force attack. | |
| Modificada | Media (4.3) | 1.0% | — | Julian Kleinhans KJ Imagelightbox2 | 15/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the KJ: Imagelightbox (kj_imagelightbox2) extension 2.0.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-2490. | |
| Modificada | Alta (7.6) | 3.0% | — | HP 8100c Digital SenderHP 9100c Digital SenderHP 9200c Digital SenderHP 9250c Digital Sender+150 | 18/3/2009 | 16/6/2026 | The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access. | |
| Modificada | Media (5.1) | 1.1% | — | HP 8100c Digital SenderHP 9100c Digital SenderHP 9200c Digital SenderHP 9250c Digital Sender+150 | 18/3/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network… | |
| Modificada | Media (4.3) | 1.0% | — | Typo3 KJ Imagelightbox2 | 28/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the KJ Image Lightbox 2 (aka kj_imagelightbox2) extension 1.4.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified "user input." | |
| Modificada | Media (6.4) | 1.2% | — | Angelinecms | 12/5/2006 | 16/6/2026 | SQL injection vulnerability in lib/adodb/server.php in AngelineCMS 0.6.5 and earlier might allow remote attackers to execute arbitrary SQL commands via the query string. | |
| Modificada | Media (5) | 2.3% | — | Angelinecms | 12/5/2006 | 16/6/2026 | AngelineCMS 0.6.5 and earlier allow remote attackers to obtain sensitive information via a direct request for (1) adodb-access.inc.php, (2) adodb-ado.inc.php, (3) adodb-ado_access.inc, (4) adodb-ado_mssql.inc.php, (5) adodb-borland_ibase, (6) adodb-csv.inc.php, (7) adodb-db2.inc.php, (8) adodb-fbsql.inc.php, (9)… |