Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.42% | — | Northernbeacheswebsites WP Gotowebinar | 25/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson WP GoToWebinar plugin <= 14.45 versions. | |
| Analizada | Alta (7.5) | 3.5% | ⚠ Explotación activa | Northgrid Proself | 18/10/2023 | 17/6/2026 | Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data,… | |
| Modificada | Alta (7.2) | 1.2% | — | Northgrid Proself | 18/8/2023 | 17/6/2026 | Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands. | |
| Modificada | Alta (7.5) | 1.0% | — | Northgrid Proself | 18/8/2023 | 17/6/2026 | Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel and perform an unintended operation. | |
| Modificada | Media (6.5) | 0.55% | — | Northern.tech Cfengine | 26/4/2023 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials. | |
| Modificada | Crítica (9.8) | 0.93% | — | Globalnorthstar Northstar Club Management | 16/9/2022 | 17/6/2026 | There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the… | |
| Modificada | Media (4.3) | 0.22% | — | Northern.tech Mender | 6/7/2022 | 17/6/2026 | The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API calls from additional client components running on the device. However, it listens on all network interfaces instead of only the localhost… | |
| Modificada | Crítica (9.8) | 1.0% | — | Northern.tech Mender | 28/4/2022 | 17/6/2026 | The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints. | |
| Modificada | Alta (8.8) | 0.48% | — | Northern.tech Mender | 28/4/2022 | 17/6/2026 | The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking. | |
| Modificada | Media (5.5) | 0.36% | — | Northern.tech Cfengine | 10/3/2022 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files. | |
| Modificada | Media (5.5) | 0.35% | — | Northern.tech Cfengine | 10/3/2022 | 17/6/2026 | Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact. | |
| Modificada | Media (5.3) | 1.8% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application. | |
| Modificada | Alta (7.5) | 0.81% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP. | |
| Modificada | Crítica (9.8) | 1.7% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication. | |
| Modificada | Alta (7.5) | 1.8% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application. | |
| Modificada | Media (6.5) | 0.81% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request. | |
| Modificada | Crítica (9.8) | 3.6% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters. | |
| Modificada | Media (5.5) | 0.21% | — | Northern.tech Cfengine | 27/10/2021 | 17/6/2026 | The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. | |
| Modificada | Media (6.5) | 0.42% | — | Northern.tech Cfengine | 27/10/2021 | 17/6/2026 | CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation. | |
| Modificada | Alta (7.5) | 1.1% | — | Northern.tech Useradm | 27/8/2021 | 17/6/2026 | The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled). | |
| Modificada | Media (4.8) | 1.1% | — | Northwestern Timelinejs | 9/7/2020 | 17/6/2026 | In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file. Most TimelineJS users… | |
| Modificada | Media (6.1) | 0.64% | — | Northern.tech Cfengine | 16/4/2020 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0. | |
| Modificada | Crítica (9.8) | 2.0% | — | Enorth Webpublisher CMS | 12/2/2020 | 17/6/2026 | SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attackers to execute arbitrary SQL commands via the cbNewsId parameter. | |
| Modificada | Alta (8.8) | 2.0% | — | Northern Cfengine | 6/6/2019 | 17/6/2026 | Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions. | |
| Modificada | Alta (7.5) | 1.4% | — | Northernnep Northern Electric & Power Inverter Firmware | 28/6/2018 | 17/6/2026 | Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/status/index/1 URI. |