Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)3.3%💥 ExploitEllucian Ethos Identity20/5/202317/6/2026
A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (5.4)0.60%—Openwrt Luci10/4/202317/6/2026
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.
ModificadaMedia (5.4)0.51%—Openwrt Luci3/11/202217/6/2026
OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.
ModificadaMedia (6.1)0.59%—Openwrt Luci25/5/20219/7/2026
The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability.
ModificadaMedia (5.3)1.7%—Openwrt Luci23/3/202017/6/2026
In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance of this report because, for instances reachable by an unauthenticated actor, the same information is available in other (more complex) ways, and there is no…
ModificadaCrítica (9.8)7.4%💥 PoCOpenwrt Luci23/5/201917/6/2026
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
ModificadaAlta (8.1)5.9%💥 PoCEllucian Banner Enterprise Identity ServicesEllucian Banner WEB Tailor14/5/201917/6/2026
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session…
ModificadaMedia (6.1)1.3%—Ellucian Banner Student11/9/201717/6/2026
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.
ModificadaCrítica (9.8)2.3%—Ellucian Banner Student11/9/201717/6/2026
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."
ModificadaMedia (5.3)2.0%—Ellucian Banner Student11/9/201717/6/2026
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests.
ModificadaMedia (6.1)1.2%—Ellucian Banner Student11/9/201717/6/2026
Cross-site scripting (XSS) vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)5.0%💥 ExploitLucidcrew Pixie3/4/201717/6/2026
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.
ModificadaMedia (6.1)0.80%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.
ModificadaMedia (6.1)0.82%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
ModificadaMedia (6.1)0.82%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
ModificadaMedia (6.1)0.80%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
ModificadaMedia (6.1)1.2%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
ModificadaMedia (5.4)0.27%—Ebiblio Andalucia20/10/201417/6/2026
The eBiblio Andalucia (aka com.bqreaders.reader.ebiblioandalucia) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6)1.4%—Scientificlinux Luci15/10/201417/6/2026
Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted cluster configuration.
ModificadaMedia (4.3)1.4%—Lucidcrew Pixie4/6/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/.
ModificadaMedia (6.2)0.38%—Scientificlinux LuciRedhat Enterprise Linux23/11/201316/6/2026
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories.
ModificadaBaja (1.9)0.25%—Scientificlinux LuciRedhat Enterprise Linux23/11/201316/6/2026
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."
ModificadaMedia (5.8)0.96%—Lucion Scan TO PDF Free25/1/201216/6/2026
The Scan to PDF Free (com.scan.to.pdf.trial) application 2.0.4 for Android does not properly protect data, which allows remote attackers to read or modify scanned files and a Google account via a crafted application.
ModificadaAlta (7.5)1.7%💥 ExploitGetpixie PixieLucidcrew Pixie8/12/201116/6/2026
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.
ModificadaMedia (5)1.9%—Lucidcrew Pixie24/9/201116/6/2026
Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files.
Orbitaley — Vulnerabilidades