Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.34% | — | Ampache | 11/11/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating catalog. This vulnerability allows an attacker to exploit CSRF attacks, potentially enabling them to change website features that… | |
| Modificada | Alta (8.4) | 0.50% | — | Ampache | 11/11/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can change the "Custom URL - Favicon". This section is not properly sanitized, allowing for the input of strings that can execute JavaScript. This issue has been… | |
| Analizada | Media (5.3) | 0.34% | — | Ampache | 11/11/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating plugins. This vulnerability allows an attacker to exploit CSRF attacks, potentially enabling them to change website features that… | |
| Analizada | Media (5.3) | 0.34% | — | Ampache | 11/11/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating controllers. This vulnerability allows an attacker to exploit CSRF attacks, potentially enabling them to change website features… | |
| Modificada | Crítica (9.8) | 0.39% | — | Renzojohnson Contact Form 7 Campaign Monitor Extension | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Renzo Johnson Contact Form 7 Campaign Monitor Extension contact-form-7-campaign-monitor-extension.This issue affects Contact Form 7 Campaign Monitor Extension: from n/a through <= 0.4.67. | |
| Analizada | Media (6.5) | 0.31% | — | Ampache | 9/10/2024 | 17/6/2026 | ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smartlist etc.). Cross-Site Request Forgery (CSRF) is an attack that forces authenticated users to submit a request to a Web application against which they are currently… | |
| Analizada | Media (4.8) | 0.55% | — | Ampache | 27/9/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playlist Name is vulnerable to a stored cross-site scripting. Version 6.6.0 fixes this issue. | |
| Analizada | Media (5.3) | 0.54% | — | Tamparongj03 Online Graduate Tracer System | 20/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Graduate Tracer System up to 1.0. Affected is an unknown function of the file /tracking/admin/fetch_genderit.php. The manipulation of the argument request leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.3) | 0.61% | — | Tamparongj03 Online Graduate Tracer System | 19/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue affects some unknown processing of the file /tracking/admin/view_csprofile.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.51% | — | Tamparongj03 Online Graduate Tracer System | 16/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /tracking/admin/fetch_it.php. The manipulation of the argument request leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.48% | — | Tamparongj03 Online Graduate Tracer System | 15/8/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/admin/add_acc.php. The manipulation of the argument name/user/position leads to cross site scripting. The attack can be… | |
| Analizada | Media (6.9) | 0.98% | — | Tamparongj03 Online Graduate Tracer System | 15/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.98% | — | Tamparongj03 Online Graduate Tracer System | 15/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the file /tracking/admin/export_it.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.55% | — | Tamparongj03 Online Graduate Tracer System | 15/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tracking/admin/view_itprofile.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.76% | — | Tamparongj03 Online Graduate Tracer System | 15/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/nbproject/. The manipulation leads to exposure of information through directory listing. The attack can be launched… | |
| Aplazada | Media (6.5) | 0.27% | — | Zoho CampaignsAI | 13/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Campaigns allows Cross-Site Scripting (XSS).This issue affects Zoho Campaigns: from n/a through 2.0.8. | |
| Aplazada | Media (5.3) | 0.86% | 💥 Exploit | Campaignmonitor Campaign MonitorAI | 27/7/2024 | 17/6/2026 | The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due the plugin not properly restricting direct access to /forms/views/admin/create.php and display_errors being enabled. This makes it possible for unauthenticated… | |
| Analizada | Media (5.4) | 0.46% | — | Ampache | 23/7/2024 | 17/6/2026 | Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the "Playlists - Democratic - Configure Democratic Playlist" feature. An attacker with Content Manager permissions can set the Name… | |
| Analizada | Crítica (9.1) | 0.79% | — | Apache Streampark | 23/7/2024 | 17/6/2026 | On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even after logout. Mitigation: all users should upgrade to 2.1.4 | |
| Modificada | Media (6.5) | 0.73% | — | Apache Streampark | 22/7/2024 | 17/6/2026 | On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 | |
| Modificada | Alta (8.8) | 1.2% | — | Apache Streampark | 18/7/2024 | 17/6/2026 | On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigation: all users should upgrade to 2.1.4 | |
| Analizada | Media (5.9) | 0.28% | — | Apache Streampark | 17/7/2024 | 17/6/2026 | In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc. Mitigation: all users… | |
| Modificada | Media (4.7) | 1.1% | — | Apache Streampark | 17/7/2024 | 17/6/2026 | In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level… | |
| Modificada | Media (4.7) | 1.6% | — | Apache Streampark | 17/7/2024 | 17/6/2026 | In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level… | |
| Analizada | Alta (8.1) | 0.64% | — | Apache Streampark | 16/7/2024 | 17/6/2026 | In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is generated using this field. However, because this sort field isn't validated, there is a risk of SQL injection vulnerability. The attacker must… |