Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.39% | — | Gopiplus Horizontal Scrolling Announcement | 16/9/2023 | 17/6/2026 | The Horizontal scrolling announcement plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'horizontal-scrolling' shortcode in versions up to, and including, 9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Alta (8) | 0.42% | — | Opennms HorizonOpennms Meridian | 23/8/2023 | 17/6/2026 | In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is vulnerable to XXE injection attacks. The solution is to upgrade to Meridian 2023.1.5 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state… | |
| Modificada | Media (6.1) | 0.80% | — | Openstack Horizon | 22/8/2023 | 17/6/2026 | Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. | |
| Modificada | Alta (8) | 2.9% | 💥 Exploit | Opennms HorizonOpennms Meridian | 17/8/2023 | 17/6/2026 | In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily escalate their privileges to ROLE_ADMIN or any other role. The solution is to upgrade to Meridian 2023.1.5 or Horizon 32.0.2 or newer. Meridian and Horizon installation… | |
| Modificada | Alta (8.8) | 0.78% | — | Opennms HorizonOpennms Meridian | 17/8/2023 | 17/6/2026 | A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code execution. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon… | |
| Modificada | Media (5.2) | 0.64% | — | Opennms HorizonOpennms Meridian | 14/8/2023 | 17/6/2026 | Multiple reflected XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms that an attacker can modify to craft a malicious XSS payload. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon… | |
| Modificada | Media (4.8) | 0.74% | — | Opennms HorizonOpennms Meridian | 14/8/2023 | 17/6/2026 | Multiple stored XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms that allow an attacker to store on database and then load on JSPs or Angular templates. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19,… | |
| Modificada | Alta (8) | 3.3% | 💥 Exploit | Opennms HorizonOpennms Meridian | 14/8/2023 | 17/6/2026 | The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation… | |
| Modificada | Media (6.1) | 0.55% | — | Opennms HorizonOpennms Meridian | 11/8/2023 | 17/6/2026 | XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which can be used for instance to force Horizon to make arbitrary HTTP requests to internal and external services. The solution is to upgrade to… | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution WP Responsive Tabs Horizontal Vertical AND Accordion Tabs | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs plugin <= 1.1.15 versions. | |
| Modificada | Media (5.3) | 0.49% | — | Vmware Horizon Client | 4/8/2023 | 17/6/2026 | VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relating to the internal network configuration. | |
| Modificada | Media (5.3) | 0.46% | — | Vmware Horizon Client | 4/8/2023 | 17/6/2026 | VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests. | |
| Modificada | Media (4.8) | 0.37% | — | Gopiplus Tiny Carousel Horizontal Slider Plus | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny carousel horizontal slider plus plugin <= 3.2 versions. | |
| Modificada | Media (6.7) | 0.30% | — | Opennms HorizonOpennms Meridian | 22/3/2023 | 17/6/2026 | A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacker to gain access to confidential information and compromise integrity. The solution is to upgrade to Meridian 2023.1.1 or Horizon 31.0.6 or newer. Meridian and Horizon… | |
| Modificada | Media (6.1) | 0.41% | — | Opennms HorizonOpennms Meridian | 23/2/2023 | 17/6/2026 | Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4 or newer. Meridian and Horizon installation instructions state that they are intended… | |
| Modificada | Media (6.1) | 0.44% | — | Opennms HorizonOpennms Meridian | 23/2/2023 | 17/6/2026 | Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for… | |
| Modificada | Media (6.1) | 0.42% | — | Opennms HorizonOpennms Meridian | 23/2/2023 | 17/6/2026 | Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation… | |
| Modificada | Media (6.5) | 0.63% | — | Opennms HorizonOpennms Meridian | 23/2/2023 | 17/6/2026 | Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation… | |
| Modificada | Media (6.1) | 0.49% | — | Opennms HorizonOpennms Meridian | 22/2/2023 | 17/6/2026 | Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation… | |
| Modificada | Media (5.4) | 0.52% | — | Horizon Project Horizon | 15/1/2023 | 17/6/2026 | A vulnerability was found in yanheven console and classified as problematic. Affected by this issue is some unknown functionality of the file horizon/static/horizon/js/horizon.instances.js. The manipulation leads to cross site scripting. The attack may be launched remotely. The patch is identified as… | |
| Modificada | Media (6.7) | 1.1% | 💥 PoC | Horizondatasys Uefi BootloaderRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+6 | 26/8/2022 | 17/6/2026 | A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this… | |
| Modificada | Crítica (9.8) | 1.8% | — | Siemens Biograph Horizon Pet/ct Systems FirmwareSiemens Magnetom Numaris X FirmwareSiemens Mammomat Revelation FirmwareSiemens Naeotom Alpha Firmware+14 | 1/6/2022 | 17/6/2026 | A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40… | |
| Modificada | Alta (7.8) | 0.24% | — | Vmware Horizon | 11/4/2022 | 17/6/2026 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file. | |
| Modificada | Alta (7.8) | 0.30% | — | Vmware Horizon | 11/4/2022 | 17/6/2026 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file. | |
| Modificada | Crítica (9.8) | 1.2% | — | Horizontcms Project Horizontcms | 5/4/2022 | 17/6/2026 | File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed that the filter was bypassed via uploading… |