Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

83 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.0%—Strangerstudios Paid Memberships PRO18/3/202117/6/2026
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5.3)1.1%—Rangerstudio Directus23/2/202117/6/2026
In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaMedia (5.3)0.70%—Rangerstudio Directus23/2/202117/6/2026
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: This vulnerability only affects products that are no longer…
ModificadaAlta (8.8)1.2%—Rangerstudio Directus23/2/202117/6/2026
In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaAlta (7.5)1.4%—Rangerstudio Directus23/2/202117/6/2026
In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of information about the user (such as email address, first name, and last name) but also the secret for 2FA if one exists. This secret can be regenerated. NOTE: This…
ModificadaAlta (7.2)1.2%—Strangerstudios Paid Memberships PRO20/5/202017/6/2026
SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.1)3.0%—Apache Ranger8/8/201917/6/2026
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.
ModificadaAlta (8.8)1.6%—Rangerstudio Directus 7 API19/7/201917/6/2026
Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthenticated users, as demonstrated by the EICAR Anti-Virus Test File.
ModificadaCrítica (9.8)1.5%—Rangerstudio Directus 7 API19/7/201917/6/2026
Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.
ModificadaMedia (5.3)1.1%—Rangerstudio Directus 719/7/201917/6/2026
interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview.
ModificadaMedia (5.3)1.5%—Rangerstudio Directus 7 API19/7/201917/6/2026
In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configuration option in which the file collection can be non-public, but this option does not apply to the thumbnailer.
ModificadaAlta (8.8)2.5%—Rangerstudio Directus 7 API19/7/201917/6/2026
In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx.
ModificadaAlta (8.8)2.6%—Rangerstudio Directus 7 API19/7/201917/6/2026
In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.
ModificadaAlta (8.8)1.9%💥 PoCWifiranger Firmware23/10/201817/6/2026
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.
ModificadaAlta (8.8)4.0%—Apache Ranger5/10/201817/6/2026
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0
ModificadaCrítica (9.8)1.3%—Rangerstudio Directus5/5/201817/6/2026
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
ModificadaAlta (7.2)4.4%—Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+19421/11/201717/6/2026
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
ModificadaAlta (7.8)0.56%—Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+19421/11/201717/6/2026
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
ModificadaMedia (6.1)2.1%—Strangerstudios Paid Memberships PRO23/10/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to…
ModificadaMedia (6.5)2.1%—Apache Ranger13/10/201717/6/2026
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
ModificadaMedia (5.9)2.6%—Apache Ranger14/6/201717/6/2026
In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.
ModificadaCrítica (9.8)4.2%—Apache Ranger14/6/201717/6/2026
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
ModificadaMedia (4.8)2.1%—Apache Ranger14/6/201717/6/2026
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.
ModificadaMedia (5.9)2.7%—Apache Ranger14/6/201717/6/2026
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
ModificadaMedia (4.8)2.1%—Apache Ranger26/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.
Orbitaley — Vulnerabilidades