Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Arialsoftware Campaign Enterprise | 10/1/2020 | 16/6/2026 | A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field. | |
| Modificada | Alta (7.5) | 1.8% | — | Arialsoftware Campaign Enterprise | 10/1/2020 | 16/6/2026 | In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization. | |
| Modificada | Alta (7.5) | 1.5% | — | Arialsoftware Campaign Enterprise | 10/1/2020 | 16/6/2026 | Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved. | |
| Modificada | Alta (7.5) | 1.9% | — | Arialsoftware Campaign Enterprise | 10/1/2020 | 16/6/2026 | Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials. | |
| Modificada | Alta (7.5) | 3.1% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. | |
| Modificada | Crítica (9.8) | 5.8% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user. | |
| Modificada | Alta (7.5) | 3.1% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Inadequate access control vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. | |
| Modificada | Alta (7.5) | 3.3% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user. | |
| Modificada | Alta (7.5) | 3.1% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper error handling vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. | |
| Modificada | Alta (7.5) | 3.2% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Insufficient input validation vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. | |
| Modificada | Media (5.4) | 0.67% | — | IBM Campaign | 17/7/2019 | 17/6/2026 | IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152857. | |
| Modificada | Media (4.3) | 2.3% | — | IBM Campaign | 19/6/2019 | 17/6/2026 | IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172. | |
| Modificada | Alta (7.8) | 0.31% | — | IBM Campaign | 5/12/2018 | 17/6/2026 | IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-Force ID: 153382. | |
| Modificada | Baja (3.3) | 0.34% | — | IBM Campaign | 9/11/2018 | 17/6/2026 | IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass security due to lack of input validation. IBM X-Force ID: 120206. | |
| Modificada | Media (5.4) | 0.85% | — | IBM Campaign | 7/9/2018 | 17/6/2026 | IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 121153. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Campaign | 7/9/2018 | 17/6/2026 | IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121152. | |
| Modificada | Media (4.3) | 0.96% | — | IBM Campaign | 27/4/2018 | 17/6/2026 | IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154. | |
| Modificada | Crítica (9.1) | 3.7% | — | Adobe Campaign | 12/4/2017 | 17/6/2026 | Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campaign database. | |
| Modificada | Media (6.1) | 1.7% | — | Adobe Campaign | 15/2/2017 | 17/6/2026 | Adobe Campaign versions 16.4 Build 8724 and earlier have a cross-site scripting (XSS) vulnerability. | |
| Modificada | Crítica (9.1) | 2.8% | — | Adobe Campaign | 15/2/2017 | 17/6/2026 | Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability. | |
| Modificada | Media (5.4) | 0.70% | — | IBM Campaign | 1/2/2017 | 17/6/2026 | IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An… | |
| Modificada | Media (6.8) | 0.64% | — | Campaign Monitor Project Campaign Monitor | 15/6/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in includes/campaignmonitor_lists.admin.inc in the Campaign Monitor module 7.x-1.0 for Drupal allow remote attackers to hijack the authentication of users for requests that (1) enable list subscriptions via a request to… | |
| Modificada | Media (5.4) | 0.27% | — | Paulalexanderformayor Paul Alexander Campaign | 16/10/2014 | 17/6/2026 | The Paul Alexander Campaign (aka hr.apps.n51261427) application 4.5.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.1% | — | Arialsoftware Campaign Enterprise | 14/8/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to execute arbitrary SQL commands via the (1) SerialNumber field to activate.asp or (2) UID field to User-Edit.asp. | |
| Modificada | Media (4.3) | 1.2% | — | Trexart Campaignmonitor | 31/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the… |