Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.8% | — | Itarian On-premiseItarian Saas Service Desk | 9/6/2022 | 17/6/2026 | The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any version prior to 6.35.37347.20040, a malicious actor (with a valid session… | |
| Modificada | Alta (7.5) | 0.82% | — | Itarian On-premiseItarian Saas Service Desk | 9/6/2022 | 17/6/2026 | Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination… | |
| Modificada | Alta (7.5) | 1.6% | — | Saasproject Booking Package | 4/4/2022 | 17/6/2026 | The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability. | |
| Modificada | Media (6.1) | 1.3% | — | Saasproject Booking Package | 24/11/2021 | 17/6/2026 | Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.3) | 0.94% | — | Thinksaas | 8/7/2021 | 17/6/2026 | Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "photodesc%5B%5D" parameters in the component "index.php?app=photo." | |
| Modificada | Crítica (9.8) | 1.9% | — | Thinksaas | 24/3/2021 | 17/6/2026 | ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands. | |
| Modificada | Media (6.1) | 0.75% | — | Thinksaas | 21/9/2019 | 17/6/2026 | An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBED element. | |
| Modificada | Media (4.8) | 0.59% | — | Thinksaas | 21/9/2019 | 17/6/2026 | An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter. | |
| Modificada | Media (5.4) | 0.67% | — | Thinksaas | 7/8/2018 | 17/6/2026 | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter. | |
| Modificada | Media (5.4) | 0.67% | — | Thinksaas | 7/8/2018 | 17/6/2026 | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter. | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Livecrm Saas Cloud | 24/1/2018 | 17/6/2026 | SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request. | |
| Modificada | Alta (7.5) | 1.8% | — | Mcafee Saas Control Console Platform | 14/3/2017 | 17/6/2026 | A directory traversal vulnerability in the web application in McAfee (now Intel Security) SaaS Control Console (SCC) Platform 6.14 before patch 1070, and 6.15 before patch 1076 allows unauthenticated users to view contents of arbitrary system files that did not have file system level read access restrictions via a… | |
| Modificada | Media (5) | 1.2% | — | Mcafee Saas Endpoint Protection | 22/8/2012 | 16/6/2026 | The Rumor technology in McAfee SaaS Endpoint Protection before 5.2.4 allows remote attackers to relay e-mail messages via unspecified vectors, as demonstrated by relaying spam. | |
| Modificada | Media (6.8) | 1.2% | — | Mcafee Saas Endpoint Protection | 10/8/2011 | 16/6/2026 | The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the MyCioScan.Scan.ReportFile parameter, as demonstrated by injecting script into a log file and executing arbitrary code using the… | |
| Modificada | Media (6.8) | 2.1% | — | Mcafee Saas Endpoint Protection | 10/8/2011 | 16/6/2026 | The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyASUtil.SecureObjectFactory.CreateSecureObject domain execution policy using a cross-site scripting (XSS) attack, execute arbitrary code using the… |