Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 41% | — | Centreon WEB | 21/8/2024 | 17/6/2026 | Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateServiceHost function. The issue… | |
| Aplazada | Media (5.3) | 0.38% | — | Patreon WordpressAI | 9/7/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon WordPress: from n/a through <= 1.9.0. | |
| Modificada | Media (6.1) | 0.33% | — | Codebard's Patron Button AND Widgets FOR Patreon | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon allows Reflected XSS.This issue affects CodeBard's Patron Button and Widgets for Patreon: from n/a through 2.2.0. | |
| Analizada | Crítica (9.6) | 1.1% | — | Centreon WEB | 3/5/2024 | 17/6/2026 | Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability. The specific flaw exists within the processing of the sysName OID in SNMP.… | |
| Analizada | Alta (8.8) | 1.4% | — | Centreon WEB | 1/4/2024 | 17/6/2026 | Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the insertGraphTemplate function. The… | |
| Analizada | Alta (7.2) | 53% | — | Centreon WEB | 1/4/2024 | 17/6/2026 | Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateContactHostCommands… | |
| Analizada | Alta (7.2) | 53% | — | Centreon WEB | 1/4/2024 | 17/6/2026 | Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateContactServiceCommands… | |
| Analizada | Alta (7.2) | 53% | — | Centreon WEB | 1/4/2024 | 17/6/2026 | Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateLCARelation function. The issue… | |
| Analizada | Alta (7.2) | 67% | — | Centreon WEB | 1/4/2024 | 17/6/2026 | Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateGroups function. The issue results… | |
| Analizada | Alta (8.8) | 72% | — | Centreon WEB | 1/4/2024 | 17/6/2026 | Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateDirectory function. The issue… | |
| Modificada | Alta (8.8) | 0.26% | — | Codebard's Patron Button AND Widgets FOR Patreon | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.9 versions. | |
| Modificada | Alta (8.8) | 0.29% | — | Patreon Wordpress | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Patreon Patreon WordPress.This issue affects Patreon WordPress: from n/a through 1.8.6. | |
| Modificada | Media (6.1) | 0.36% | — | Codebard Patron Button AND Widgets FOR Patreon | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability (requires PHP 8.x) in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.9 versions. | |
| Modificada | Crítica (9.1) | 0.87% | — | Patreon Flutter Downloader | 19/9/2023 | 17/6/2026 | A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and… | |
| Modificada | Media (6.1) | 0.38% | — | Codebard's Patron Button AND Widgets FOR Patreon | 5/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.8 versions. | |
| Modificada | Alta (8.8) | 76% | — | Centreon | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a… | |
| Modificada | Alta (8.8) | 2.9% | — | Centreon | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a… | |
| Modificada | Alta (8.8) | 76% | — | Centreon | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper validation of a user-supplied string before… | |
| Modificada | Alta (8.8) | 2.9% | — | Centreon | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a… | |
| Modificada | Alta (8.8) | 76% | — | Centreon | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a… | |
| Modificada | Alta (8.8) | 76% | — | Centreon | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a… | |
| Modificada | Alta (8.8) | 85% | — | Centreon | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the lack of proper validation of a… | |
| Modificada | Crítica (9.8) | 0.83% | — | Centreon | 2/11/2022 | 17/6/2026 | A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated remotely. The name of the patch is… | |
| Modificada | Crítica (9.8) | 0.85% | — | Discourse Patreon | 26/10/2022 | 17/6/2026 | Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabled, an improper authentication vulnerability could be used to take control of a victim's forum account. This vulnerability is patched in commit number 846d012151514b35ce42a1636c7d70f6dcee879e of the… | |
| Modificada | Media (5.4) | 0.77% | — | Centreon | 6/10/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML via a crafted payload injected into the Service>Templates service_alias parameter. |