Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 3.3% | 💥 Exploit | Ellucian Ethos Identity | 20/5/2023 | 17/6/2026 | A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.4) | 0.60% | — | Openwrt Luci | 10/4/2023 | 17/6/2026 | LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm. | |
| Modificada | Media (5.4) | 0.51% | — | Openwrt Luci | 3/11/2022 | 17/6/2026 | OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments. | |
| Modificada | Media (6.1) | 0.59% | — | Openwrt Luci | 25/5/2021 | 9/7/2026 | The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability. | |
| Modificada | Media (5.3) | 1.7% | — | Openwrt Luci | 23/3/2020 | 17/6/2026 | In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance of this report because, for instances reachable by an unauthenticated actor, the same information is available in other (more complex) ways, and there is no… | |
| Modificada | Crítica (9.8) | 7.4% | 💥 PoC | Openwrt Luci | 23/5/2019 | 17/6/2026 | In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability. | |
| Modificada | Alta (8.1) | 5.9% | 💥 PoC | Ellucian Banner Enterprise Identity ServicesEllucian Banner WEB Tailor | 14/5/2019 | 17/6/2026 | An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session… | |
| Modificada | Media (6.1) | 1.3% | — | Ellucian Banner Student | 11/9/2017 | 17/6/2026 | Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ellucian Banner Student | 11/9/2017 | 17/6/2026 | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset." | |
| Modificada | Media (5.3) | 2.0% | — | Ellucian Banner Student | 11/9/2017 | 17/6/2026 | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests. | |
| Modificada | Media (6.1) | 1.2% | — | Ellucian Banner Student | 11/9/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 5.0% | 💥 Exploit | Lucidcrew Pixie | 3/4/2017 | 17/6/2026 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg. | |
| Modificada | Media (6.1) | 0.80% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack. | |
| Modificada | Media (6.1) | 0.82% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack. | |
| Modificada | Media (6.1) | 0.82% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | |
| Modificada | Media (6.1) | 0.80% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack. | |
| Modificada | Media (6.1) | 1.2% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. | |
| Modificada | Media (5.4) | 0.27% | — | Ebiblio Andalucia | 20/10/2014 | 17/6/2026 | The eBiblio Andalucia (aka com.bqreaders.reader.ebiblioandalucia) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6) | 1.4% | — | Scientificlinux Luci | 15/10/2014 | 17/6/2026 | Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted cluster configuration. | |
| Modificada | Media (4.3) | 1.4% | — | Lucidcrew Pixie | 4/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/. | |
| Modificada | Media (6.2) | 0.38% | — | Scientificlinux LuciRedhat Enterprise Linux | 23/11/2013 | 16/6/2026 | Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories. | |
| Modificada | Baja (1.9) | 0.25% | — | Scientificlinux LuciRedhat Enterprise Linux | 23/11/2013 | 16/6/2026 | Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets." | |
| Modificada | Media (5.8) | 0.96% | — | Lucion Scan TO PDF Free | 25/1/2012 | 16/6/2026 | The Scan to PDF Free (com.scan.to.pdf.trial) application 2.0.4 for Android does not properly protect data, which allows remote attackers to read or modify scanned files and a Google account via a crafted application. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Getpixie PixieLucidcrew Pixie | 8/12/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI. | |
| Modificada | Media (5) | 1.9% | — | Lucidcrew Pixie | 24/9/2011 | 16/6/2026 | Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files. |