Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

66 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.88%—Livehelperchat Live Helper Chat8/12/202117/6/2026
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.5)0.44%—Livehelperchat Live Helper Chat7/12/202117/6/2026
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaAlta (7.5)0.83%—Baidu Xuperchain19/7/202117/6/2026
An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.
ModificadaMedia (6.1)1.0%—Livehelperchat Live Helper Chat2/10/202017/6/2026
Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO.
ModificadaMedia (6.1)1.1%—Livehelperchat Live Helper Chat2/10/202017/6/2026
Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode.
ModificadaMedia (4.8)0.59%—Grabaperch Perch28/10/201717/6/2026
Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account.
ModificadaMedia (6.1)1.1%—Livehelperchat Live Helper Chat17/7/201717/6/2026
Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users.
ModificadaAlta (7.5)11%💥 ExploitCOM Perchadownloadsattach25/5/201016/6/2026
Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)13%💥 ExploitCOM Perchafieldsattach25/5/201016/6/2026
Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)16%💥 ExploitCOM Perchagallery25/5/201016/6/2026
Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)11%💥 ExploitCOM Perchaimageattach25/5/201016/6/2026
Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)16%💥 ExploitCOM Perchacategoriestree25/5/201016/6/2026
Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)1.00%💥 ExploitCOM Perchagallery23/2/201016/6/2026
SQL injection vulnerability in the PerchaGallery (com_perchagallery) component before 1.5b for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an editunidad action to index.php.
ModificadaAlta (7.5)1.0%💥 ExploitED Charkow Supercharged Linking18/11/200916/6/2026
SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5)1.5%—Sleeperchat25/1/200616/6/2026
SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2) chat_if.php.
ModificadaMedia (4.3)1.7%💥 ExploitSleeperchat25/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter.
Orbitaley — Vulnerabilidades