Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

80 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.43%—Totalonlinesolutions Advanced Webhost Billing System8/1/202117/6/2026
Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.
ModificadaAlta (7.8)0.47%—Bbraun Onlinesuite Application Package6/11/202017/6/2026
A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute code on the system as a high privileged user.
ModificadaCrítica (9.8)2.0%—Bbraun Onlinesuite Application Package6/11/202017/6/2026
A relative path traversal attack in the B. Braun OnlineSuite Version AP 3.0 and earlier allows unauthenticated attackers to upload or download arbitrary files.
ModificadaAlta (7.8)0.98%—Bbraun Onlinesuite Application Package6/11/202017/6/2026
An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaAlta (8.8)0.78%—Pagelines13/9/201917/6/2026
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
ModificadaAlta (7.5)6.6%—Microsoft .net CoreMicrosoft Asp.net CoreMicrosoft System.io.pipelines13/9/201817/6/2026
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
ModificadaMedia (5.4)0.27%—Pegasus Airlines Project Pegasus Airlines21/10/201417/6/2026
The Pegasus Airlines (aka com.wPegasusAirlines) application 0.84.13503.96707 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Headlines News India Project Headlines News India20/10/201417/6/2026
The Headlines news India (aka com.dreamstep.wHEADLINESNEWSINDIA) application 0.21.13219.95110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Iata Airlines International25/9/201417/6/2026
The Airlines International (aka org.iata.IAMagazine) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)1.3%—Sabreairlinesolutions Crew ManagementSabreairlinesolutions Crew OperationsSabreairlinesolutions Crew PlanningSabreairlinesolutions Crew Services+126/7/201417/6/2026
Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
ModificadaMedia (5)2.8%💥 ExploitEpic Games Unreal TournamentFrontlines Fuel OF WAR19/8/200916/6/2026
Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure.
ModificadaAlta (7.5)1.9%💥 ExploitXlinesoft Phprunner19/3/200916/6/2026
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
ModificadaAlta (7.5)2.1%💥 ExploitXlinesoft Phprunner19/3/200916/6/2026
Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.
ModificadaMedia (4.3)2.2%💥 ExploitRightscripts Text Lines Rearrange Script27/2/200916/6/2026
Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled, allows remote attackers to read arbitrary local files via directory traversal sequences in the filename parameter.
ModificadaAlta (7.5)1.7%💥 ExploitElinestudio Site Composer25/6/200816/6/2026
Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp.
ModificadaMedia (4.3)1.7%💥 ExploitElinestudio Site Composer25/6/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4) txtEmail parameters to login.asp.
ModificadaAlta (7.5)2.9%💥 ExploitElinestudio Site Composer25/6/200816/6/2026
Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/.
ModificadaMedia (5)2.5%💥 ExploitElinestudio Site Composer25/6/200816/6/2026
eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2) common2.asp in cms/include/, which reveals the database path.
ModificadaMedia (4.3)1.0%—Geek-palace.com Lineshout20/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)8.0%💥 ExploitCardinal CMS Project Cardinal CMSRedlinesoft Lanai CMSSitex CMS Project Sitex CMSSyntax CMS Project Syntax CMS1/10/200716/6/2026
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown…
ModificadaBaja (2.1)0.33%—Xlinesoft Phprunner17/11/200616/6/2026
XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.
ModificadaMedia (6.8)2.1%💥 ExploitPhpnuke Myheadlines6/9/200616/6/2026
Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the myh_op parameter to modules.php.
ModificadaMedia (4.3)1.8%💥 ExploitEctools OnlineshopAI16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.
ModificadaMedia (5)1.8%—Xlinesoft Asprunner31/12/200416/6/2026
ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.
Orbitaley — Vulnerabilidades