Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.0% | — | Strangerstudios Paid Memberships PRO | 18/3/2021 | 17/6/2026 | SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5.3) | 1.1% | — | Rangerstudio Directus | 23/2/2021 | 17/6/2026 | In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (5.3) | 0.70% | — | Rangerstudio Directus | 23/2/2021 | 17/6/2026 | In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: This vulnerability only affects products that are no longer… | |
| Modificada | Alta (8.8) | 1.2% | — | Rangerstudio Directus | 23/2/2021 | 17/6/2026 | In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (7.5) | 1.4% | — | Rangerstudio Directus | 23/2/2021 | 17/6/2026 | In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of information about the user (such as email address, first name, and last name) but also the secret for 2FA if one exists. This secret can be regenerated. NOTE: This… | |
| Modificada | Alta (7.2) | 1.2% | — | Strangerstudios Paid Memberships PRO | 20/5/2020 | 17/6/2026 | SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.1) | 3.0% | — | Apache Ranger | 8/8/2019 | 17/6/2026 | Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix. | |
| Modificada | Alta (8.8) | 1.6% | — | Rangerstudio Directus 7 API | 19/7/2019 | 17/6/2026 | Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthenticated users, as demonstrated by the EICAR Anti-Virus Test File. | |
| Modificada | Crítica (9.8) | 1.5% | — | Rangerstudio Directus 7 API | 19/7/2019 | 17/6/2026 | Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php. | |
| Modificada | Media (5.3) | 1.1% | — | Rangerstudio Directus 7 | 19/7/2019 | 17/6/2026 | interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview. | |
| Modificada | Media (5.3) | 1.5% | — | Rangerstudio Directus 7 API | 19/7/2019 | 17/6/2026 | In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configuration option in which the file collection can be non-public, but this option does not apply to the thumbnailer. | |
| Modificada | Alta (8.8) | 2.5% | — | Rangerstudio Directus 7 API | 19/7/2019 | 17/6/2026 | In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx. | |
| Modificada | Alta (8.8) | 2.6% | — | Rangerstudio Directus 7 API | 19/7/2019 | 17/6/2026 | In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution. | |
| Modificada | Alta (8.8) | 1.9% | 💥 PoC | Wifiranger Firmware | 23/10/2018 | 17/6/2026 | An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account. | |
| Modificada | Alta (8.8) | 4.0% | — | Apache Ranger | 5/10/2018 | 17/6/2026 | UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0 | |
| Modificada | Crítica (9.8) | 1.3% | — | Rangerstudio Directus | 5/5/2018 | 17/6/2026 | Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql. | |
| Modificada | Alta (7.2) | 4.4% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (7.8) | 0.56% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Media (6.1) | 2.1% | — | Strangerstudios Paid Memberships PRO | 23/10/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to… | |
| Modificada | Media (6.5) | 2.1% | — | Apache Ranger | 13/10/2017 | 17/6/2026 | In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role. | |
| Modificada | Media (5.9) | 2.6% | — | Apache Ranger | 14/6/2017 | 17/6/2026 | In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table. | |
| Modificada | Crítica (9.8) | 4.2% | — | Apache Ranger | 14/6/2017 | 17/6/2026 | Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior. | |
| Modificada | Media (4.8) | 2.1% | — | Apache Ranger | 14/6/2017 | 17/6/2026 | Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies. | |
| Modificada | Media (5.9) | 2.7% | — | Apache Ranger | 14/6/2017 | 17/6/2026 | Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true. | |
| Modificada | Media (4.8) | 2.1% | — | Apache Ranger | 26/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies. |