Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.45% | — | Damienharper Auditor-bundle | 10/9/2024 | 17/6/2026 | auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because `%source_label%` in twig macro is not escaped. Therefore script tags can be inserted… | |
| Analizada | Alta (8.8) | 5.2% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module. | |
| Analizada | Alta (8.8) | 4.0% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report. | |
| Analizada | Alta (8.8) | 5.3% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module. | |
| Analizada | Alta (8.8) | 4.4% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard. | |
| Analizada | Alta (8.8) | 4.0% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option. | |
| Analizada | Alta (8.8) | 4.7% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration. | |
| Analizada | Alta (8.8) | 4.7% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option. | |
| Analizada | Media (5.4) | 3.1% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard. | |
| Analizada | Alta (8.8) | 7.4% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording. | |
| Analizada | Alta (8.8) | 7.4% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option. | |
| Modificada | Media (6.1) | 0.45% | — | Openfind MailauditOpenfind Mailgates | 15/7/2024 | 17/6/2026 | The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Openfind MailgatesAIOpenfind MailauditAI | 17/6/2024 | 17/6/2026 | Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system commands and execute them on the remote server. | |
| Modificada | Media (5.5) | 0.38% | — | Adobe Audition | 13/6/2024 | 17/6/2026 | Audition versions 24.2, 23.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to crash the application, leading to a denial of service. Exploitation of this issue requires user… | |
| Modificada | Media (5.5) | 0.49% | — | Adobe Audition | 13/6/2024 | 17/6/2026 | Audition versions 24.2, 23.6.4 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Aplazada | Alta (7.8) | 0.19% | — | Finalwire Airda ExtremeAIFinalwire Aida64 EngineerAIFinalwire Aida64 BusinessAIFinalwire Aida64 Network AuditAI | 10/6/2024 | 7/10/2026 | An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components. | |
| Analizada | Media (5.5) | 0.46% | — | Zohocorp Manageengine Adaudit Plus | 27/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings. | |
| Analizada | Media (4.2) | 0.37% | — | Zohocorp Manageengine Adaudit Plus | 27/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration. | |
| Analizada | Alta (7.2) | 2.2% | — | Zohocorp Manageengine Adaudit Plus | 22/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature. |