Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.6% | — | Jgroups JgroupRedhat Jboss Enterprise Application Platform | 28/9/2013 | 16/6/2026 | The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials. | |
| Modificada | Baja (3.5) | 0.95% | — | Organic Groups Project Organic Groups | 3/12/2012 | 16/6/2026 | The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved. | |
| Modificada | Media (5) | 1.6% | — | Moshe Weitzman Organic Groups | 14/8/2012 | 16/6/2026 | The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private group titles via a request through the Views module. | |
| Modificada | Baja (2.1) | 1.7% | — | Moshe Weitzman Organic Groups | 27/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title. | |
| Modificada | Media (6.8) | 2.6% | — | Moshe Weitzman Organic Groups | 27/6/2012 | 16/6/2026 | The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact. | |
| Modificada | Media (4.3) | 1.2% | — | Ezra Barnett Gildesgame OG Subgroups | 24/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Subgroups for Organic Groups (OG) module 5.x before 5.x-4.0 and 5.x before 5.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified node titles. | |
| Modificada | Baja (3.5) | 1.0% | — | Moshe Weitzman Organic Groups | 9/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authenticated users, with create or edit group nodes permissions, to inject arbitrary web script or HTML via the User-Agent HTTP header, a… | |
| Modificada | Alta (7.5) | 1.1% | — | Permis COM Groups | 17/8/2009 | 16/6/2026 | SQL injection vulnerability in the Permis (com_groups) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (9.3) | 2.8% | — | Mcafee Groupshield | 5/5/2009 | 16/6/2026 | McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an… | |
| Modificada | Baja (3.5) | 0.84% | — | Drupal Organic Groups Module | 9/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote authenticated users, with group owner permissions, to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Organic Groups Project Organic Groups | 9/7/2008 | 16/6/2026 | The Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote attackers to obtain sensitive information (private group names) via unspecified vectors. | |
| Modificada | Alta (7.5) | 4.4% | — | Carlos Sanchez Valle MynewsgroupsPHP Layers Menu | 1/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Carlos Sanchez Valle Mynewsgroups | 3/7/2006 | 16/6/2026 | SQL injection vulnerability in tree.php in MyNewsGroups 0.6 allows remote attackers to execute arbitrary SQL commands via the grp_id parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Carlos Sanchez Valle Mynewsgroups | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyNewsGroups 0.4 and 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the subject of a newsgroup post, which is not properly handled by (1) myarticles.php, (2) search.php, (3) stats.php, or (4) standard.lib.php. |