Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.56% | — | MojoliciousAI | 24/3/2024 | 17/6/2026 | The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar. | |
| Modificada | Media (5.4) | 0.31% | — | Mojofywp WP Affiliate Disclosure | 5/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This issue affects WP Affiliate Disclosure: from n/a through 1.2.7. | |
| Modificada | Media (5.3) | 0.30% | — | Mojotv Base64captcha | 11/12/2023 | 17/6/2026 | When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct. | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Mojoportal | 2/10/2023 | 17/6/2026 | Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component. | |
| Modificada | Crítica (9.8) | 1.8% | — | Mojoportal | 2/10/2023 | 17/6/2026 | An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component. | |
| Modificada | Crítica (9.8) | 1.8% | — | Mojoportal | 2/10/2023 | 17/6/2026 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mojoportal | 2/10/2023 | 17/6/2026 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function. | |
| Modificada | Alta (8.1) | 0.98% | — | Showmojo Mojobox Firmware | 20/7/2023 | 17/6/2026 | ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker… | |
| Modificada | Media (4.8) | 0.42% | — | Qumos Mojoplug Slide Panel | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Qumos MojoPlug Slide Panel plugin <= 1.1.2 versions. | |
| Modificada | Media (4.3) | 0.73% | — | Mojoportal | 9/2/2023 | 17/6/2026 | An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx | |
| Modificada | Media (5.3) | 0.70% | — | Mojoportal | 9/2/2023 | 17/6/2026 | An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled. | |
| Modificada | Media (5.4) | 0.63% | — | Mojoportal | 9/2/2023 | 17/6/2026 | Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtCompanyName parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Mojoportal | 9/2/2023 | 17/6/2026 | Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability. | |
| Modificada | Media (6.1) | 32% | 💥 Exploit | Mojoportal | 9/2/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters. | |
| Modificada | Crítica (9.8) | 0.86% | — | Mojojson Project Mojojson | 3/2/2023 | 17/6/2026 | An issue was found in MojoJson v1.2.3 allows attackers to execute arbitary code via the destroy function. | |
| Modificada | Crítica (9.8) | 0.95% | — | Mojojson Project Mojojson | 3/2/2023 | 17/6/2026 | Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function. | |
| Modificada | Media (6.5) | 1.2% | — | Mojoportal | 3/10/2022 | 9/7/2026 | mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system. | |
| Modificada | Alta (8.8) | 1.4% | — | Mojoportal | 30/9/2022 | 9/7/2026 | mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file. | |
| Modificada | Crítica (9.8) | 1.2% | — | Transtek Mojodat Fixed Asset Management | 13/9/2022 | 17/6/2026 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request. | |
| Modificada | Media (5.3) | 0.77% | — | Transtek Mojodat Fixed Asset Management | 13/9/2022 | 17/6/2026 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other users' data upon a successful login request. | |
| Modificada | Alta (7.5) | 0.96% | — | Transtek Mojodat Fixed Asset Management | 13/9/2022 | 17/6/2026 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext passwords upon a successful login request. | |
| Modificada | Crítica (9.8) | 1.1% | — | Transtek Mojodat Fixed Asset Management | 13/9/2022 | 17/6/2026 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authorization. | |
| Modificada | Media (6.1) | 0.78% | — | Kibokolabs Moolamojo | 10/9/2021 | 17/6/2026 | The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.4.1. | |
| Modificada | Crítica (9.8) | 4.3% | — | Karma-mojo Project Karma-mojo | 2/4/2020 | 17/6/2026 | karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. | |
| Modificada | Crítica (9.8) | 2.4% | — | Mojohaus Exec Maven | 6/1/2020 | 17/6/2026 | The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element). |