Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.2%—Tangro Business Workflow18/12/202017/6/2026
tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction is enforced in the browser (client-side) and can be circumvented. This allows an attacker to upload any file as an attachment to a…
ModificadaMedia (4.3)0.74%—Tangro Business Workflow18/12/202017/6/2026
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.
ModificadaMedia (6.5)0.66%—Tangro Business Workflow18/12/202017/6/2026
Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not contain an expiration timestamp.
ModificadaMedia (4.3)0.58%—Tangro Business Workflow18/12/202017/6/2026
In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.
ModificadaMedia (5.3)0.81%—Untangle Firewall NG12/11/202017/6/2026
Untangle Firewall NG before 16.0 uses MD5 for passwords.
ModificadaMedia (4.8)0.52%—Untangle NG Firewall14/11/201917/6/2026
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
ModificadaMedia (4.8)0.52%—Untangle NG Firewall14/11/201917/6/2026
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.
ModificadaAlta (7.2)1.9%—Untangle NG Firewall14/11/201917/6/2026
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
ModificadaAlta (7.2)0.91%—Untangle NG Firewall14/11/201917/6/2026
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.
ModificadaMedia (4.3)1.4%—Textangular20/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in textAngular-sanitize.js in textAngular before 1.3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the editor.
ModificadaMedia (5.4)0.27%—Yourtango Your Tango19/10/201417/6/2026
The Your Tango (aka com.your.tango) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.9)0.39%—Alex Launi Tangerine20/10/201016/6/2026
The (1) tangerine and (2) tangerine-properties scripts in Tangerine 0.3.2.2 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
ModificadaMedia (4.3)1.1%—Tangocms8/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Html::textarea function in application/libraries/Html.php in TangoCMS 2.x before 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the value parameter, related to the Contact module.
ModificadaMedia (4.3)1.0%—Tangocms10/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in the hook_cntrlr_error_output function in modules/page/hooks/listeners.php in the admincp component in TangoCMS 2.2.x (aka Eagle) before 2.2.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from…
ModificadaMedia (6)0.48%—Tangocms4/2/200916/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in TangoCMS before 2.2.0 allow remote attackers to hijack the authentication of administrators.
ModificadaAlta (7.5)2.4%💥 ExploitYannick Tanguy Else IF CMS9/10/200716/6/2026
ELSEIF CMS Beta 0.6 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by uploading a .php file via externe/swfupload/upload.php. NOTE: it could be argued that this…
ModificadaMedia (4.3)3.8%💥 ExploitYannick Tanguy Else IF CMS9/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) repertimage parameter to utilisateurs/vousetesbannis.php, the (2) elseifvotetxtresultatduvote parameter to utilisateurs/votesresultats.php, and the (3)…
ModificadaMedia (5)2.8%💥 ExploitYannick Tanguy Else IF CMS9/10/200716/6/2026
ELSEIF CMS Beta 0.6 allows remote attackers to obtain sensitive information (full path) via unspecified vectors to utilisateurs/votesresultats.php.
ModificadaAlta (7.5)9.3%💥 ExploitYannick Tanguy Else IF CMS9/10/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenus parameter to (a) contenus.php; the (2) tpelseifportalrepertoire parameter to (b) votes.php, (c) espaceperso.php, (d) enregistrement.php, (e) commentaire.php, and…
ModificadaMedia (4.3)1.7%💥 ExploitTangora Portal CMS22/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter in a search page, as demonstrated using (1) page1631.aspx and (2) page496.aspx.
ModificadaAlta (7.5)4.5%—Wildtangent Webdriver29/1/200416/6/2026
Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename.
ModificadaAlta (7.5)7.8%💥 ExploitTerascript Wintango Application Server27/8/200316/6/2026
Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference.
ModificadaAlta (7.2)0.35%—Mostang Sane19/7/200116/6/2026
Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.
Orbitaley — Vulnerabilidades