Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

93 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.56%—MojoliciousAI24/3/202417/6/2026
The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar.
ModificadaMedia (5.4)0.31%—Mojofywp WP Affiliate Disclosure5/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This issue affects WP Affiliate Disclosure: from n/a through 1.2.7.
ModificadaMedia (5.3)0.30%—Mojotv Base64captcha11/12/202317/6/2026
When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct.
ModificadaMedia (6.1)1.3%💥 ExploitMojoportal2/10/202317/6/2026
Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component.
ModificadaCrítica (9.8)1.8%—Mojoportal2/10/202317/6/2026
An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.
ModificadaCrítica (9.8)1.8%—Mojoportal2/10/202317/6/2026
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.
ModificadaCrítica (9.8)1.6%—Mojoportal2/10/202317/6/2026
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.
ModificadaAlta (8.1)0.98%—Showmojo Mojobox Firmware20/7/202317/6/2026
ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker…
ModificadaMedia (4.8)0.42%—Qumos Mojoplug Slide Panel22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Qumos MojoPlug Slide Panel plugin <= 1.1.2 versions.
ModificadaMedia (4.3)0.73%—Mojoportal9/2/202317/6/2026
An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx
ModificadaMedia (5.3)0.70%—Mojoportal9/2/202317/6/2026
An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled.
ModificadaMedia (5.4)0.63%—Mojoportal9/2/202317/6/2026
Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtCompanyName parameter.
ModificadaAlta (8.8)1.2%—Mojoportal9/2/202317/6/2026
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.
ModificadaMedia (6.1)32%💥 ExploitMojoportal9/2/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters.
ModificadaCrítica (9.8)0.86%—Mojojson Project Mojojson3/2/202317/6/2026
An issue was found in MojoJson v1.2.3 allows attackers to execute arbitary code via the destroy function.
ModificadaCrítica (9.8)0.95%—Mojojson Project Mojojson3/2/202317/6/2026
Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.
ModificadaMedia (6.5)1.2%—Mojoportal3/10/20229/7/2026
mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system.
ModificadaAlta (8.8)1.4%—Mojoportal30/9/20229/7/2026
mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file.
ModificadaCrítica (9.8)1.2%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.
ModificadaMedia (5.3)0.77%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other users' data upon a successful login request.
ModificadaAlta (7.5)0.96%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext passwords upon a successful login request.
ModificadaCrítica (9.8)1.1%—Transtek Mojodat Fixed Asset Management13/9/202217/6/2026
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authorization.
ModificadaMedia (6.1)0.78%—Kibokolabs Moolamojo10/9/202117/6/2026
The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.4.1.
ModificadaCrítica (9.8)4.3%—Karma-mojo Project Karma-mojo2/4/202017/6/2026
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
ModificadaCrítica (9.8)2.4%—Mojohaus Exec Maven6/1/202017/6/2026
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element).
Orbitaley — Vulnerabilidades