Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 35% | — | Schneider-electric Spacelogic C-bus Toolkit | 4/10/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command. | |
| Modificada | Media (6.1) | 0.76% | 💥 Exploit | Agilelogix Post Timeline | 4/9/2023 | 17/6/2026 | The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.69% | 💥 Exploit | Agilelogix Store Locator | 4/9/2023 | 17/6/2026 | The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “ticket queue watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.72% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “topology data service” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.72% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 0.73% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |
| Modificada | Alta (8.8) | 1.6% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | |
| Modificada | Alta (8.8) | 1.6% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. |