Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

114 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)25%💥 PoCBalasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+2611/11/202123/9/2026
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network…
ModificadaAlta (8.8)2.0%—Heateor Sassy Social Share21/10/202117/6/2026
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file. This can be…
ModificadaCrítica (9.8)3.8%—Ivanti Desktop&server ManagementIvanti Service Manager Heat Remote Control6/8/202017/6/2026
Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet.
ModificadaAlta (8.8)0.89%—Redhat OpenstackOpenstack Tripleo Heat Templates30/7/201817/6/2026
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
ModificadaMedia (5.5)0.41%—Openstack HeatRedhat Openstack27/7/201817/6/2026
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
ModificadaAlta (7.2)0.95%—Single Theater Booking Script Project Single Theater Booking Script28/12/201717/6/2026
PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter.
ModificadaMedia (4.8)0.50%—Single Theater Booking Script Project Single Theater Booking Script28/12/201717/6/2026
PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.
ModificadaAlta (8.8)0.46%—Single Theater Booking Script Project Single Theater Booking Script28/12/201717/6/2026
PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.
ModificadaMedia (4.8)0.50%—Single Theater Booking Script Project Single Theater Booking Script28/12/201717/6/2026
PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.
ModificadaCrítica (9.8)2.2%💥 ExploitSingle Theater Booking Script Project Single Theater Booking Script13/12/201717/6/2026
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
ModificadaCrítica (9.8)2.2%💥 ExploitMultiplex Movie Theater Booking Script Project Multiplex Movie Theater Booking Script13/12/201717/6/2026
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.
ModificadaAlta (7.8)1.8%—Solarcontrols Heating Control Downloader14/8/201717/6/2026
An Uncontrolled Search Path Element issue was discovered in Solar Controls Heating Control Downloader (HCDownloader) Version 1.0.1.15 and prior. An uncontrolled search path element has been identified, which could allow an attacker to execute arbitrary code on a target system using a malicious DLL file.
ModificadaMedia (4.3)1.5%—Openstack Heat4/11/201617/6/2026
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
ModificadaMedia (6.1)3.4%💥 ExploitHeat-trackr Project Heat-trackr10/10/201617/6/2026
Reflected XSS in wordpress plugin heat-trackr v1.0
ModificadaAlta (7.5)2.4%—Redhat OpenstackOpenstack Tripleo Heat Templates15/4/201617/6/2026
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private…
ModificadaAlta (7.5)1.7%—Openstack Tripleo Heat Templates11/4/201617/6/2026
The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.
ModificadaCrítica (9.8)1.9%—Ephiphanyheathdata Cardio Server27/12/201517/6/2026
The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.
ModificadaMedia (6.8)1.1%💥 ExploitLabsmedia Clickheat18/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php.
ModificadaMedia (6.8)0.61%—Viralheat Argyle Social1/1/201516/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Argyle Social 2011-04-26 allow remote attackers to hijack the authentication of administrators for requests that (1) modify credentials via the role parameter to users/create/, (2) modify rules via the terms field in stream_filter_rule JSON data to…
ModificadaBaja (3.5)1.6%—Openstack Heat23/5/201417/6/2026
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
ModificadaMedia (4)1.7%—Openstack Heat14/12/201317/6/2026
The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.
ModificadaMedia (4)1.0%—Openstack Heat14/12/201317/6/2026
The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via…
ModificadaAlta (7.5)1.1%💥 ExploitFrontrange Heat9/10/200916/6/2026
Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaAlta (7.5)1.00%💥 ExploitScripts-for-sites EZ Gaming Cheats23/2/200916/6/2026
SQL injection vulnerability in view_reviews.php in Scripts for Sites (SFS) EZ Gaming Cheats allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (9.3)5.6%💥 ExploitHeathcosoft MP3 Trackmaker20/1/200916/6/2026
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file.
Orbitaley — Vulnerabilidades