Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 2.1% | — | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+16 | 12/4/2021 | 17/6/2026 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Facade Ignition | 12/1/2021 | 17/6/2026 | Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2. | |
| Modificada | Alta (7.5) | 1.2% | — | Inductiveautomation Ignition Gateway | 31/7/2020 | 17/6/2026 | The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all versions prior to 8.0.13). | |
| Modificada | Alta (7.5) | 14% | — | Inductiveautomation Ignition Gateway | 9/6/2020 | 17/6/2026 | The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.5% | — | Inductiveautomation Ignition Gateway | 9/6/2020 | 17/6/2026 | The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an… | |
| Modificada | Alta (7.5) | 20% | — | Inductiveautomation Ignition Gateway | 9/6/2020 | 17/6/2026 | The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information. | |
| Modificada | Crítica (9.8) | 1.5% | — | Facade Ignition | 7/6/2020 | 17/6/2026 | The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a consequence of the CVE-2021-43996 fix. | |
| Modificada | Alta (7.5) | 1.3% | — | Inductiveautomation Ignition Gateway | 28/4/2020 | 17/6/2026 | An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions prior to 8.0.10), causing a denial-of-service condition. | |
| Modificada | Media (5) | 1.1% | — | Inductiveautomation Ignition | 3/4/2015 | 17/6/2026 | Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack. | |
| Modificada | Media (4) | 1.3% | — | Inductiveautomation Ignition | 3/4/2015 | 17/6/2026 | Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests. | |
| Modificada | Media (6.4) | 2.3% | — | Inductiveautomation Ignition | 3/4/2015 | 17/6/2026 | Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation. | |
| Modificada | Baja (2.1) | 0.33% | — | Inductiveautomation Ignition | 3/4/2015 | 17/6/2026 | Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5) | 1.3% | — | Inductiveautomation Ignition | 3/4/2015 | 17/6/2026 | Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception, as demonstrated by pathname information. | |
| Modificada | Media (4.3) | 1.1% | — | Inductiveautomation Ignition | 3/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Inductive Automation Ignition 7.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.3% | — | Launchpad Ignition | 28/12/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the blog parameter to (1) comment.php and (2) view.php. | |
| Modificada | Alta (7.5) | 2.5% | — | THE Ignition Project Ignitionserver | 17/5/2005 | 16/6/2026 | mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions. | |
| Modificada | Baja (2.1) | 0.49% | — | THE Ignition Project Ignitionserver | 17/5/2005 | 16/6/2026 | mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service. | |
| Modificada | Media (6) | 1.8% | — | THE Ignition Project Ignitionserver | 31/12/2004 | 16/6/2026 | The Ignition Project ignitionServer 0.1.2 through 0.1.2-R2 allows remote authenticated users with local IRC operator privileges to obtain global IRC operator privileges by using the unofficial umode command with the +ORD argument. | |
| Modificada | Alta (7.5) | 2.5% | — | THE Ignition Project Ignitionserver | 31/12/2004 | 16/6/2026 | Unknown vulnerability in The Ignition Project ignitionServer 0.1.2 through 0.3.1, with the linking service enabled, allows remote attackers to bypass authentication. |