Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.2% | — | Admidio | 29/7/2024 | 17/6/2026 | Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code Execution Vulnerability in the Message module of the Admidio Application, where it is possible to upload a PHP file in the attachment. The uploaded file can be… | |
| Analizada | Alta (8.8) | 0.93% | — | Admidio | 29/7/2024 | 17/6/2026 | Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.9, there is an SQL Injection in the `/adm_program/modules/ecards/ecard_send.php` source file of the Admidio Application. The SQL Injection results in a compromise of the application's database.… | |
| Modificada | Media (6.1) | 0.70% | — | Admidio | 22/11/2023 | 17/6/2026 | Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Media (6.5) | 0.60% | — | Admidio | 6/8/2023 | 17/6/2026 | Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11. | |
| Modificada | Alta (7.2) | 1.0% | — | Admidio | 16/7/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository admidio/admidio prior to 4.2.10. | |
| Modificada | Media (5.4) | 0.41% | — | Admidio | 23/6/2023 | 17/6/2026 | Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9. | |
| Modificada | Baja (3.5) | 0.42% | — | Admidio | 23/6/2023 | 17/6/2026 | Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9. | |
| Modificada | Alta (7.8) | 0.46% | — | Admidio | 23/6/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9. | |
| Modificada | Media (5.4) | 0.48% | — | Admidio | 5/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository admidio/admidio prior to 4.2.8. | |
| Modificada | Media (5.4) | 0.57% | — | Admidio | 28/6/2022 | 17/6/2026 | Admidio 4.1.2 version is affected by stored cross-site scripting (XSS). | |
| Modificada | Alta (7.1) | 1.0% | — | Admidio | 19/3/2022 | 17/6/2026 | Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9. | |
| Modificada | Media (6.1) | 5.1% | 💥 Exploit | Admidio | 7/12/2021 | 17/6/2026 | Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this… | |
| Modificada | Alta (8.8) | 1.6% | — | Admidio | 20/5/2021 | 17/6/2026 | Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload. A php web shell can be uploaded via the Documents & Files upload feature. Someone with upload permissions could rename the php shell with… | |
| Modificada | Crítica (9.8) | 3.0% | — | Un4seen Bassmidi | 16/10/2020 | 17/6/2026 | The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability. An attacker may exploit this to execute code on the target machine. A failure in exploitation leads to a denial of service. | |
| Modificada | Alta (7.5) | 1.5% | — | Admidio | 24/4/2020 | 17/6/2026 | SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacker without logging in, can send a GET request with arbitrary SQL queries appended to the cookie parameter and execute SQL queries. The… | |
| Modificada | Alta (7.8) | 1.7% | — | Mindwerks Wildmidi | 2/1/2018 | 17/6/2026 | The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Media (6.5) | 8.4% | 💥 Exploit | Mindwerks Wildmidi | 17/8/2017 | 17/6/2026 | The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file. | |
| Modificada | Media (6.5) | 5.5% | 💥 Exploit | Mindwerks Wildmidi | 17/8/2017 | 17/6/2026 | The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file. | |
| Modificada | Alta (7.5) | 9.7% | 💥 Exploit | Mindwerks Wildmidi | 17/8/2017 | 17/6/2026 | The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Mindwerks Wildmidi | 17/8/2017 | 17/6/2026 | The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file. | |
| Modificada | Media (5.5) | 0.96% | — | Timidity++ Project Timidity++ | 31/7/2017 | 17/6/2026 | The play_midi function in playmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mid file. NOTE: CPU consumption might be relevant when using the --background option. | |
| Modificada | Media (5.5) | 1.1% | — | Timidity++ Project Timidity++ | 31/7/2017 | 17/6/2026 | The resample_gauss function in resample.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mid file. NOTE: a crash might be relevant when using the --background option. NOTE: the TiMidity++ README.alsaseq documentation suggests a setuid-root… | |
| Modificada | Media (5.5) | 1.1% | — | Timidity++ Project Timidity++ | 31/7/2017 | 17/6/2026 | The insert_note_steps function in readmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mid file. NOTE: a crash might be relevant when using the --background option. | |
| Modificada | Media (4.5) | 2.6% | 💥 Exploit | Admidio | 16/5/2017 | 17/6/2026 | admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts. |