Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.3% | — | Xxyopen Novel-plus | 18/9/2023 | 17/6/2026 | SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list. | |
| Modificada | Crítica (9.8) | 1.0% | — | Xxyopen Novel-plus | 11/9/2023 | 17/6/2026 | novel-plus 3.6.2 is vulnerable to SQL Injection. | |
| Modificada | Crítica (9.8) | 0.72% | — | Xxyopen Novel-plus | 14/8/2023 | 9/7/2026 | novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Media (4.8) | 0.37% | — | Nosegraze Novelist | 28/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <= 1.2.0 versions. | |
| Modificada | Alta (8.8) | 0.80% | — | Xxyopen Novel-plus | 14/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in novel-plus 3.6.2. Affected by this vulnerability is an unknown functionality of the file /category/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 0.75% | — | Xxyopen Novel-plus | 14/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in novel-plus 3.6.2. Affected is an unknown function of the file /news/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (8.8) | 0.80% | — | Xxyopen Novel-plus | 14/4/2023 | 17/6/2026 | A vulnerability was found in novel-plus 3.6.2. It has been rated as critical. This issue affects some unknown processing of the file /author/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.73% | — | Xxyopen Novel-plus | 23/3/2023 | 17/6/2026 | A vulnerability was found in novel-plus 3.6.2. It has been classified as critical. This affects an unknown part of the file /common/sysFile/list. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.89% | — | Xxyopen Novel-plus | 23/3/2023 | 17/6/2026 | A vulnerability was found in novel-plus 3.6.2 and classified as critical. Affected by this issue is some unknown functionality of the file DictController.java. The manipulation of the argument orderby leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (7.2) | 0.87% | — | Xxyopen Novel-plus | 23/3/2023 | 17/6/2026 | A vulnerability has been found in novel-plus 3.6.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file common/log/list. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Crítica (9.8) | 1.0% | — | Xxyopen Novel-plus | 23/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in novel-plus 3.6.2. Affected is the function MenuService of the file sys/menu/list. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 1.3% | — | Xxyopen Novel-plus | 1/9/2022 | 17/6/2026 | Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session. | |
| Modificada | Alta (7.5) | 0.45% | — | Xxyopen Novel-plus | 1/9/2022 | 17/6/2026 | Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API. | |
| Modificada | Crítica (9.8) | 0.90% | — | Xxyopen Novel-plus | 17/8/2022 | 17/6/2026 | Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java. | |
| Modificada | Crítica (9.8) | 1.1% | — | Xxyopen Novel-plus | 13/5/2022 | 17/6/2026 | Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files. | |
| Modificada | Alta (7.5) | 1.1% | — | Xxyopen Novel-plus | 5/5/2022 | 17/6/2026 | novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Xxyopen Novel-plus | 28/4/2022 | 17/6/2026 | novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. | |
| Modificada | Crítica (9.8) | 1.2% | — | Xxyopen Novel-plus | 10/2/2022 | 17/6/2026 | Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input. | |
| Modificada | Media (5.3) | 2.1% | — | Novel Boutique House-plus Project Novel Boutique House-plus | 29/4/2021 | 17/6/2026 | Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1 allows attackers to read arbitrary files via the filePath parameter. | |
| Modificada | Media (5) | 1.3% | — | Nextcloud ServerOpensuse Backports SLENovell Suse Linux Enterprise Server | 4/2/2020 | 17/6/2026 | An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application. | |
| Modificada | Baja (3.5) | 0.98% | — | QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 31/1/2020 | 17/6/2026 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Novell Zenworks Configuration Management | 25/1/2020 | 16/6/2026 | Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information. | |
| Modificada | Media (6.1) | 0.72% | — | Novell Zenworks Configuration Management | 25/1/2020 | 16/6/2026 | Novell ZENworks Configuration Management before 11.2.4 allows XSS. | |
| Modificada | Alta (7.5) | 3.2% | — | EglibcNovell Suse Linux Enterprise ServerDebian LinuxCanonical Ubuntu Linux+1 | 31/12/2019 | 16/6/2026 | The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. | |
| Modificada | Alta (7.8) | 0.51% | — | QemuDebian LinuxNovell Open Desktop ServerNovell Open Enterprise Server | 30/12/2019 | 16/6/2026 | A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus… |