Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.62% | — | Whisperfish Blurhash-rs | 19/9/2023 | 17/6/2026 | blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. In version 0.1.1, the blurhash parsing code may panic due to multiple panic-guarded out-of-bounds accesses on untrusted input. In a… | |
| Modificada | Alta (7.5) | 0.87% | — | Whisperfish Phonenumber | 19/9/2023 | 17/6/2026 | phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of `rust-phonenumber`, this may get… | |
| Modificada | Media (6.8) | 0.32% | — | Catfishcms Project Catfishcms | 27/6/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions via /index.php/admin/index/modifymanage.html. | |
| Modificada | Crítica (9.8) | 0.74% | — | Lionfish CMS Project Lionfish CMS | 2/3/2023 | 17/6/2026 | A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function goods_detail of the file ApiController.class.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.5) | 0.94% | — | Eclipse Glassfish | 27/1/2023 | 22/7/2026 | In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code.… | |
| Modificada | Media (6.1) | 0.55% | — | Hfish Project Hfish | 26/1/2023 | 17/6/2026 | An issue was discovered in HFish 0.5.1. When a payload is inserted where the name is entered, XSS code is triggered when the administrator views the information. | |
| Modificada | Crítica (9.8) | 28% | — | Fishbowlinventory Fishbowl | 19/8/2022 | 17/6/2026 | A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload. | |
| Modificada | Media (4.3) | 0.31% | — | Starfish Rich Review | 5/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an attacker to delete reviews. | |
| Modificada | Alta (8.8) | 2.4% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource… | |
| Modificada | Crítica (9.8) | 5.5% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting.… | |
| Modificada | Crítica (9.3) | 1.3% | — | Fishtank Project Fishtank | 11/7/2022 | 17/6/2026 | The freefood89/Fishtank repository through 2015-06-24 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.8) | 1.5% | — | Atlassian CrucibleAtlassian Fisheye | 16/3/2022 | 17/6/2026 | Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via… | |
| Modificada | Alta (7.5) | 1.3% | — | Atlassian CrucibleAtlassian Fisheye | 16/3/2022 | 17/6/2026 | Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9. | |
| Modificada | Media (6.1) | 0.73% | — | Atlassian CrucibleAtlassian Fisheye | 16/3/2022 | 17/6/2026 | The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability. | |
| Modificada | Media (4.3) | 0.88% | — | Atlassian CrucibleAtlassian Fisheye | 16/3/2022 | 17/6/2026 | The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability. | |
| Modificada | Alta (7.8) | 1.5% | — | Fishshell FishFedoraproject FedoraDebian Linux | 14/3/2022 | 17/6/2026 | fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory… | |
| Modificada | Media (4.3) | 0.77% | — | Atlassian CrucibleAtlassian Fisheye | 14/3/2022 | 17/6/2026 | The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability. | |
| Modificada | Alta (7.2) | 1.5% | — | Starfish Rich Review | 27/12/2021 | 17/6/2026 | The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue | |
| Modificada | Media (6.1) | 0.56% | — | Catfish-cms Catfish CMS | 15/12/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is allowed). | |
| Modificada | Alta (8.8) | 0.42% | — | Catfish-cms Catfish CMS | 15/12/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column. | |
| Modificada | Alta (7.5) | 1.1% | — | Myfwc Fish | Hunt FL | 8/9/2021 | 17/6/2026 | An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions. | |
| Modificada | Media (4.3) | 0.81% | — | Myfwc Fish | Hunt FL | 8/9/2021 | 17/6/2026 | An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app versions 3.8.0 and earlier allows a remote authenticated attacker to retrieve other people's personal information and images of their hunting/fishing licenses. | |
| Modificada | Media (6.1) | 0.93% | — | Oracle Glassfish Server | 25/6/2021 | 17/6/2026 | Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious… | |
| Modificada | Media (6.1) | 0.66% | — | Catfish-cms Catfish CMS | 23/6/2021 | 17/6/2026 | A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "announcement_gonggao" parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Rainbowfishsoftware Pacsone Server | 3/2/2021 | 17/6/2026 | PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure. |