Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.31% | — | Katacontainers Runtime | 19/5/2020 | 17/6/2026 | Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and… | |
| Modificada | Media (6.5) | 0.37% | — | Katacontainers Runtime | 19/5/2020 | 17/6/2026 | An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS. | |
| Modificada | Alta (8.8) | 1.4% | — | Atutor Acontent | 16/3/2020 | 17/6/2026 | An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload restrictions. | |
| Modificada | Media (4.3) | 7.3% | 💥 Exploit | Alkacon Opencms Apollo Template | 27/8/2019 | 17/6/2026 | In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp. | |
| Modificada | Media (6.1) | 3.1% | 💥 Exploit | Alkacon Opencms | 27/8/2019 | 17/6/2026 | In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Alkacon Opencms Apollo Template | 27/8/2019 | 17/6/2026 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Alkacon Opencms Apollo Template | 27/8/2019 | 17/6/2026 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. | |
| Modificada | Crítica (9.8) | 4.8% | — | Deltacontrols Entelibus Firmware | 26/8/2019 | 17/6/2026 | Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possibly cause a denial of service via unspecified vectors. | |
| Modificada | Crítica (9.8) | 84% | 💥 Exploit | Deltek Maconomy | 24/5/2019 | 17/6/2026 | Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI. | |
| Modificada | Alta (7.8) | 1.0% | — | Alkacon Opencms | 8/5/2019 | 17/6/2026 | Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name. | |
| Modificada | Media (6.1) | 0.77% | — | Alkacon Opencms | 8/5/2019 | 17/6/2026 | Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is… | |
| Modificada | Crítica (9.8) | 1.4% | — | Beaconmedaes Scroll Medical AIR Systems Firmware | 6/6/2018 | 17/6/2026 | In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that is accessible without authentication. | |
| Modificada | Alta (7.5) | 1.3% | — | Beaconmedaes Scroll Medical AIR Systems Firmware | 24/5/2018 | 17/6/2026 | In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, by accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access information in the application without authenticating. | |
| Modificada | Crítica (9.8) | 1.3% | — | Beaconmedaes Scroll Medical AIR Systems Firmware | 24/5/2018 | 17/6/2026 | In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner. | |
| Modificada | Media (4.6) | 1.3% | 💥 Exploit | Alkacon Opencms | 20/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or HTML via a malicious SVG image. | |
| Modificada | Alta (8.8) | 2.1% | 💥 Exploit | Alkacon Opencms | 20/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack the authentication of administrative users for requests that perform privilege escalation. Note: It is argued that OpenCMS allows only registered users to upload… | |
| Modificada | Media (4.3) | 1.9% | — | Alkacon Opencms | 19/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to system/modules/org.opencms.workplace.help/jsptemplates/help_head.jsp, (2) workplaceresource parameter to… | |
| Modificada | Media (4.7) | 0.36% | — | Alstom E-terracontrol | 1/12/2013 | 16/6/2026 | The DNP Master Driver in Alstom e-terracontrol 3.5, 3.6, and 3.7 allows physically proximate attackers to cause a denial of service (infinite loop and DNP3 service disruption) via crafted input over a serial line. | |
| Modificada | Alta (7.8) | 1.5% | — | Alstom E-terracontrol | 13/10/2013 | 16/6/2026 | Alstom e-terracontrol 3.5, 3.6, and 3.7 allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets. | |
| Modificada | Media (4.3) | 1.9% | — | Alkacon Opencms | 9/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms before 8.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to system/workplace/views/admin/admin-main.jsp or the (2) requestedResource parameter to system/login/index.html. | |
| Modificada | Media (6.5) | 2.0% | — | Atutor Acontent | 22/10/2012 | 16/6/2026 | user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168. | |
| Modificada | Media (6.5) | 2.7% | 💥 Exploit | Atutor Acontent | 22/10/2012 | 16/6/2026 | SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQL commands via the field parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-5167. | |
| Modificada | Media (4.3) | 2.1% | — | Atutor Acontent | 22/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent before 1.2-2 allow remote attackers to inject arbitrary web script or HTML via the (1) pathext, (2) popup, (3) framed, or (4) file parameter. | |
| Modificada | Alta (7.5) | 3.4% | — | Atutor Acontent | 22/10/2012 | 16/6/2026 | ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inline_editor_submit.php or (2) course_category/index_inline_editor_submit.php. | |
| Modificada | Alta (7.5) | 4.7% | 💥 Exploit | Atutor Acontent | 22/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/index_inline_editor_submit.php or (2) user/index_inline_editor_submit.php; or (3) id parameter to user/user_password.php. |