Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.88% | — | Livehelperchat Live Helper Chat | 8/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.5) | 0.44% | — | Livehelperchat Live Helper Chat | 7/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Alta (7.5) | 0.83% | — | Baidu Xuperchain | 19/7/2021 | 17/6/2026 | An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature. | |
| Modificada | Media (6.1) | 1.0% | — | Livehelperchat Live Helper Chat | 2/10/2020 | 17/6/2026 | Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO. | |
| Modificada | Media (6.1) | 1.1% | — | Livehelperchat Live Helper Chat | 2/10/2020 | 17/6/2026 | Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode. | |
| Modificada | Media (4.8) | 0.59% | — | Grabaperch Perch | 28/10/2017 | 17/6/2026 | Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account. | |
| Modificada | Media (6.1) | 1.1% | — | Livehelperchat Live Helper Chat | 17/7/2017 | 17/6/2026 | Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | COM Perchadownloadsattach | 25/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | COM Perchafieldsattach | 25/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | COM Perchagallery | 25/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | COM Perchaimageattach | 25/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | COM Perchacategoriestree | 25/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | COM Perchagallery | 23/2/2010 | 16/6/2026 | SQL injection vulnerability in the PerchaGallery (com_perchagallery) component before 1.5b for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an editunidad action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | ED Charkow Supercharged Linking | 18/11/2009 | 16/6/2026 | SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.5% | — | Sleeperchat | 25/1/2006 | 16/6/2026 | SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2) chat_if.php. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Sleeperchat | 25/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter. |