Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

109 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.42%—Northernbeacheswebsites WP Gotowebinar25/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson WP GoToWebinar plugin <= 14.45 versions.
AnalizadaAlta (7.5)3.5%⚠ Explotación activaNorthgrid Proself18/10/202317/6/2026
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data,…
ModificadaAlta (7.2)1.2%—Northgrid Proself18/8/202317/6/2026
Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands.
ModificadaAlta (7.5)1.0%—Northgrid Proself18/8/202317/6/2026
Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel and perform an unintended operation.
ModificadaMedia (6.5)0.55%—Northern.tech Cfengine26/4/202317/6/2026
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
ModificadaCrítica (9.8)0.93%—Globalnorthstar Northstar Club Management16/9/202217/6/2026
There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the…
ModificadaMedia (4.3)0.22%—Northern.tech Mender6/7/202217/6/2026
The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API calls from additional client components running on the device. However, it listens on all network interfaces instead of only the localhost…
ModificadaCrítica (9.8)1.0%—Northern.tech Mender28/4/202217/6/2026
The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.
ModificadaAlta (8.8)0.48%—Northern.tech Mender28/4/202217/6/2026
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.
ModificadaMedia (5.5)0.36%—Northern.tech Cfengine10/3/202217/6/2026
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
ModificadaMedia (5.5)0.35%—Northern.tech Cfengine10/3/202217/6/2026
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
ModificadaMedia (5.3)1.8%—Globalnorthstar Northstar Club Management4/2/202217/6/2026
Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application.
ModificadaAlta (7.5)0.81%—Globalnorthstar Northstar Club Management4/2/202217/6/2026
Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.
ModificadaCrítica (9.8)1.7%—Globalnorthstar Northstar Club Management4/2/202217/6/2026
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.
ModificadaAlta (7.5)1.8%—Globalnorthstar Northstar Club Management4/2/202217/6/2026
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.
ModificadaMedia (6.5)0.81%—Globalnorthstar Northstar Club Management4/2/202217/6/2026
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.
ModificadaCrítica (9.8)3.6%—Globalnorthstar Northstar Club Management4/2/202217/6/2026
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.
ModificadaMedia (5.5)0.21%—Northern.tech Cfengine27/10/202117/6/2026
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
ModificadaMedia (6.5)0.42%—Northern.tech Cfengine27/10/202117/6/2026
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
ModificadaAlta (7.5)1.1%—Northern.tech Useradm27/8/202117/6/2026
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled).
ModificadaMedia (4.8)1.1%—Northwestern Timelinejs9/7/202017/6/2026
In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file. Most TimelineJS users…
ModificadaMedia (6.1)0.64%—Northern.tech Cfengine16/4/202017/6/2026
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.
ModificadaCrítica (9.8)2.0%—Enorth Webpublisher CMS12/2/202017/6/2026
SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attackers to execute arbitrary SQL commands via the cbNewsId parameter.
ModificadaAlta (8.8)2.0%—Northern Cfengine6/6/201917/6/2026
Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.
ModificadaAlta (7.5)1.4%—Northernnep Northern Electric & Power Inverter Firmware28/6/201817/6/2026
Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/status/index/1 URI.
Orbitaley — Vulnerabilidades