Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.2% | — | Tangro Business Workflow | 18/12/2020 | 17/6/2026 | tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction is enforced in the browser (client-side) and can be circumvented. This allows an attacker to upload any file as an attachment to a… | |
| Modificada | Media (4.3) | 0.74% | — | Tangro Business Workflow | 18/12/2020 | 17/6/2026 | An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required. | |
| Modificada | Media (6.5) | 0.66% | — | Tangro Business Workflow | 18/12/2020 | 17/6/2026 | Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not contain an expiration timestamp. | |
| Modificada | Media (4.3) | 0.58% | — | Tangro Business Workflow | 18/12/2020 | 17/6/2026 | In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them. | |
| Modificada | Media (5.3) | 0.81% | — | Untangle Firewall NG | 12/11/2020 | 17/6/2026 | Untangle Firewall NG before 16.0 uses MD5 for passwords. | |
| Modificada | Media (4.8) | 0.52% | — | Untangle NG Firewall | 14/11/2019 | 17/6/2026 | When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS. | |
| Modificada | Media (4.8) | 0.52% | — | Untangle NG Firewall | 14/11/2019 | 17/6/2026 | When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields. | |
| Modificada | Alta (7.2) | 1.9% | — | Untangle NG Firewall | 14/11/2019 | 17/6/2026 | The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user. | |
| Modificada | Alta (7.2) | 0.91% | — | Untangle NG Firewall | 14/11/2019 | 17/6/2026 | The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user. | |
| Modificada | Media (4.3) | 1.4% | — | Textangular | 20/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in textAngular-sanitize.js in textAngular before 1.3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the editor. | |
| Modificada | Media (5.4) | 0.27% | — | Yourtango Your Tango | 19/10/2014 | 17/6/2026 | The Your Tango (aka com.your.tango) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.9) | 0.39% | — | Alex Launi Tangerine | 20/10/2010 | 16/6/2026 | The (1) tangerine and (2) tangerine-properties scripts in Tangerine 0.3.2.2 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Media (4.3) | 1.1% | — | Tangocms | 8/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Html::textarea function in application/libraries/Html.php in TangoCMS 2.x before 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the value parameter, related to the Contact module. | |
| Modificada | Media (4.3) | 1.0% | — | Tangocms | 10/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the hook_cntrlr_error_output function in modules/page/hooks/listeners.php in the admincp component in TangoCMS 2.2.x (aka Eagle) before 2.2.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from… | |
| Modificada | Media (6) | 0.48% | — | Tangocms | 4/2/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in TangoCMS before 2.2.0 allow remote attackers to hijack the authentication of administrators. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Yannick Tanguy Else IF CMS | 9/10/2007 | 16/6/2026 | ELSEIF CMS Beta 0.6 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by uploading a .php file via externe/swfupload/upload.php. NOTE: it could be argued that this… | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Yannick Tanguy Else IF CMS | 9/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) repertimage parameter to utilisateurs/vousetesbannis.php, the (2) elseifvotetxtresultatduvote parameter to utilisateurs/votesresultats.php, and the (3)… | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Yannick Tanguy Else IF CMS | 9/10/2007 | 16/6/2026 | ELSEIF CMS Beta 0.6 allows remote attackers to obtain sensitive information (full path) via unspecified vectors to utilisateurs/votesresultats.php. | |
| Modificada | Alta (7.5) | 9.3% | 💥 Exploit | Yannick Tanguy Else IF CMS | 9/10/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenus parameter to (a) contenus.php; the (2) tpelseifportalrepertoire parameter to (b) votes.php, (c) espaceperso.php, (d) enregistrement.php, (e) commentaire.php, and… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Tangora Portal CMS | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter in a search page, as demonstrated using (1) page1631.aspx and (2) page496.aspx. | |
| Modificada | Alta (7.5) | 4.5% | — | Wildtangent Webdriver | 29/1/2004 | 16/6/2026 | Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Terascript Wintango Application Server | 27/8/2003 | 16/6/2026 | Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference. | |
| Modificada | Alta (7.2) | 0.35% | — | Mostang Sane | 19/7/2001 | 16/6/2026 | Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned. |