Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

63 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.2%—Opensourcepos Open Source Point OF Sale28/7/202217/6/2026
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
ModificadaMedia (5.9)3.8%—Opensource-socialnetwork Open Source Social Network30/3/202017/6/2026
An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert…
ModificadaMedia (6.1)0.85%—Opensource Classified ADS Script Project Opensource Classified ADS Script21/3/201917/6/2026
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field.
ModificadaMedia (6.5)1.4%—Opensource Classified ADS Script Project Opensource Classified ADS Script21/3/201917/6/2026
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory.
ModificadaMedia (5.3)1.0%—Opensource Classified ADS Script Project Opensource Classified ADS Script21/3/201917/6/2026
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form.
AnalizadaAlta (8.8)97%⚠ Explotación activaThinkphpOpensourcebms Open Source Background Management SystemZzzcms Zzzphp24/2/201917/6/2026
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
ModificadaCrítica (9.8)1.6%—Phpkaiyuancms Phpopensourcecms31/8/201817/6/2026
phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.
ModificadaCrítica (9.8)3.0%—Opensource Classified ADS Script Project Opensource Classified ADS Script13/12/201717/6/2026
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
ModificadaMedia (4.3)2.0%—Opensource Technologies Responsive Logo Slideshow14/3/201416/6/2026
Cross-site scripting (XSS) vulnerability in the Responsive Logo Slideshow plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the "URL and Image" field.
ModificadaMedia (5.8)0.57%—Opensourceclassifieds4/11/201216/6/2026
Open Source Classifieds does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
ModificadaAlta (7.8)2.6%—AsteriskAsterisk Open SourceAsterisk OpensourceSangoma Asterisk+18/9/200916/6/2026
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of…
ModificadaAlta (7.5)2.1%—MGB Opensource Guestbook19/1/200716/6/2026
SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.2%—Geonetwork Opensource26/10/200616/6/2026
SQL injection vulnerability in GeoNetwork opensource before 2.0.3 allows remote attackers to execute arbitrary SQL commands, and complete a login, via unspecified vectors.