Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 2.7% | 💥 Exploit | Odoo | 22/5/2019 | 17/6/2026 | Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote). | |
| Modificada | Alta (8.8) | 7.8% | — | Odoo | 9/4/2019 | 17/6/2026 | Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request. | |
| Modificada | Media (6.1) | 1.0% | — | Odoo | 9/4/2019 | 17/6/2026 | Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name. | |
| Modificada | Media (6.5) | 1.4% | — | Odoo | 9/4/2019 | 17/6/2026 | Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request. | |
| Modificada | Alta (8.8) | 1.0% | — | Odoo | 4/7/2017 | 17/6/2026 | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users. | |
| Modificada | Crítica (9.8) | 3.4% | — | Odoo | 4/7/2017 | 17/6/2026 | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used. | |
| Modificada | Media (6.5) | 3.6% | 💥 Exploit | Odoo | 4/7/2017 | 17/6/2026 | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used. | |
| Modificada | Media (6.5) | 5.7% | 💥 Exploit | Odoo | 4/6/2017 | 17/6/2026 | Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Wesley Destailleur Todoo Forum | 13/5/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id_post or (2) pg parameter. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Wesley Destailleur Todoo Forum | 13/5/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_post or (2) pg parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Todoomasters Todoo Forum | 8/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in todooforum.php in Todoo Forum 2.0 allows remote attackers to inject arbitrary web script or HTML via the id_forum parameter in a post action. | |
| Modificada | Alta (7.5) | 2.9% | — | Voodoo Circle | 14/5/2007 | 16/6/2026 | Multiple off-by-one errors in VooDoo cIRCle before 1.1.beta27 allow remote attackers to cause a denial of service (connection loss) or possibly execute arbitrary code via a (1) DNS name response of the exact length as a buffer; or a long (2) channel name, (3) partyline channel name, or unspecified vectors in crafted… | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Voc-project Voodoo Chat | 31/12/2006 | 16/6/2026 | Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Voc-project Voodoo Chat | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter. | |
| Modificada | Media (5) | 2.1% | — | Voodoo Circle | 2/5/2005 | 16/6/2026 | Buffer overflow in VooDoo cIRCle BOTNET before 1.0.33 allows remote authenticated attackers to cause a denial of service (client crash) via a crafted packet. |