Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.2% | — | Opensourcepos Open Source Point OF Sale | 28/7/2022 | 17/6/2026 | Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page. | |
| Modificada | Media (5.9) | 3.8% | — | Opensource-socialnetwork Open Source Social Network | 30/3/2020 | 17/6/2026 | An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert… | |
| Modificada | Media (6.1) | 0.85% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field. | |
| Modificada | Media (6.5) | 1.4% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory. | |
| Modificada | Media (5.3) | 1.0% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form. | |
| Analizada | Alta (8.8) | 97% | ⚠ Explotación activa | ThinkphpOpensourcebms Open Source Background Management SystemZzzcms Zzzphp | 24/2/2019 | 17/6/2026 | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. | |
| Modificada | Crítica (9.8) | 1.6% | — | Phpkaiyuancms Phpopensourcecms | 31/8/2018 | 17/6/2026 | phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter. | |
| Modificada | Crítica (9.8) | 3.0% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 13/12/2017 | 17/6/2026 | Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. | |
| Modificada | Media (4.3) | 2.0% | — | Opensource Technologies Responsive Logo Slideshow | 14/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Responsive Logo Slideshow plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the "URL and Image" field. | |
| Modificada | Media (5.8) | 0.57% | — | Opensourceclassifieds | 4/11/2012 | 16/6/2026 | Open Source Classifieds does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function. | |
| Modificada | Alta (7.8) | 2.6% | — | AsteriskAsterisk Open SourceAsterisk OpensourceSangoma Asterisk+1 | 8/9/2009 | 16/6/2026 | The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of… | |
| Modificada | Alta (7.5) | 2.1% | — | MGB Opensource Guestbook | 19/1/2007 | 16/6/2026 | SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Geonetwork Opensource | 26/10/2006 | 16/6/2026 | SQL injection vulnerability in GeoNetwork opensource before 2.0.3 allows remote attackers to execute arbitrary SQL commands, and complete a login, via unspecified vectors. |