Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Ikiwiki5/6/201917/6/2026
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
ModificadaAlta (8.8)1.00%—Tikiwiki Cms/groupware15/1/201917/6/2026
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
ModificadaAlta (7.5)1.1%—Hyuki Yukiwiki15/11/201817/6/2026
YukiWiki 2.1.3 and earlier does not process a particular request properly that may allow consumption of large amounts of CPU and memory resources and may result in causing a denial of service condition.
ModificadaMedia (6.1)0.79%—Hyuki Yukiwiki15/11/201817/6/2026
Cross-site scripting vulnerability in YukiWiki 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.68%—Tikiwiki Cms/groupware13/8/201817/6/2026
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
ModificadaMedia (5.4)0.68%—Tikiwiki Cms/groupware13/8/201817/6/2026
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.
ModificadaCrítica (9.8)3.3%—IkiwikiDebian Linux13/4/201817/6/2026
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
ModificadaMedia (5.3)1.1%—IkiwikiDebian Linux13/4/201817/6/2026
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
ModificadaMedia (6.5)0.91%—Ikiwiki10/4/201817/6/2026
The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.
ModificadaMedia (5.4)0.50%—Tikiwiki Cms/groupware9/3/201817/6/2026
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
ModificadaMedia (5.4)0.54%—Tikiwiki Cms/groupware21/2/201817/6/2026
The Calendar component in Tiki 17.1 allows HTML injection.
ModificadaMedia (5.4)0.52%—Tikiwiki Cms/groupware16/2/201817/6/2026
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
ModificadaMedia (6.1)0.64%—Tikiwiki Cms/groupware6/2/201817/6/2026
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
ModificadaAlta (8.8)1.6%—Kiwi Project Kiwi14/12/201717/6/2026
examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
ModificadaAlta (8)0.51%—Tikiwiki Cms/groupware30/9/201717/6/2026
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For…
ModificadaAlta (8)0.50%—Tikiwiki Cms/groupware30/9/201717/6/2026
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
ModificadaMedia (6.1)0.65%—Tikiwiki Cms/groupware26/6/201717/6/2026
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
ModificadaMedia (6.1)0.95%—Tikiwiki Cms/groupware31/5/201717/6/2026
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.
ModificadaAlta (7.5)2.1%—Ikiwiki13/2/201717/6/2026
ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, which allows remote attackers to revert certain changes by leveraging permissions to change the page before the revision was made.
ModificadaAlta (7.5)1.8%—Tikiwiki Cms/groupware20/1/201717/6/2026
A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner URL field.
ModificadaMedia (6.1)1.3%—Tikiwiki Cms/groupware23/12/201617/6/2026
Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don't have the input sanitized, related to tiki-setup.php and article_image.php. The impact is XSS.
ModificadaMedia (6.1)1.5%—IkiwikiDebian Linux10/5/201617/6/2026
Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message.
ModificadaAlta (7.5)1.3%—Wikiwiki Project Wikiwiki21/4/201517/6/2026
SQL injection vulnerability in the WikiWiki module before 6.x-1.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.9%—Kiwix21/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in Kiwix before 0.9.1, when using kiwix-serve, allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to /search.
ModificadaMedia (5.4)0.27%—Ninjakiwi Sas\9/9/201417/6/2026
The SAS: Zombie Assault 3 (aka com.ninjakiwi.sas3zombieassault) application 2.56 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades