Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
114 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 25% | 💥 PoC | Balasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+26 | 11/11/2021 | 23/9/2026 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network… | |
| Modificada | Alta (8.8) | 2.0% | — | Heateor Sassy Social Share | 21/10/2021 | 17/6/2026 | Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file. This can be… | |
| Modificada | Crítica (9.8) | 3.8% | — | Ivanti Desktop&server ManagementIvanti Service Manager Heat Remote Control | 6/8/2020 | 17/6/2026 | Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet. | |
| Modificada | Alta (8.8) | 0.89% | — | Redhat OpenstackOpenstack Tripleo Heat Templates | 30/7/2018 | 17/6/2026 | A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials. | |
| Modificada | Media (5.5) | 0.41% | — | Openstack HeatRedhat Openstack | 27/7/2018 | 17/6/2026 | An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information. | |
| Modificada | Alta (7.2) | 0.95% | — | Single Theater Booking Script Project Single Theater Booking Script | 28/12/2017 | 17/6/2026 | PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter. | |
| Modificada | Media (4.8) | 0.50% | — | Single Theater Booking Script Project Single Theater Booking Script | 28/12/2017 | 17/6/2026 | PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php. | |
| Modificada | Alta (8.8) | 0.46% | — | Single Theater Booking Script Project Single Theater Booking Script | 28/12/2017 | 17/6/2026 | PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php. | |
| Modificada | Media (4.8) | 0.50% | — | Single Theater Booking Script Project Single Theater Booking Script | 28/12/2017 | 17/6/2026 | PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Single Theater Booking Script Project Single Theater Booking Script | 13/12/2017 | 17/6/2026 | Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Multiplex Movie Theater Booking Script Project Multiplex Movie Theater Booking Script | 13/12/2017 | 17/6/2026 | Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter. | |
| Modificada | Alta (7.8) | 1.8% | — | Solarcontrols Heating Control Downloader | 14/8/2017 | 17/6/2026 | An Uncontrolled Search Path Element issue was discovered in Solar Controls Heating Control Downloader (HCDownloader) Version 1.0.1.15 and prior. An uncontrolled search path element has been identified, which could allow an attacker to execute arbitrary code on a target system using a malicious DLL file. | |
| Modificada | Media (4.3) | 1.5% | — | Openstack Heat | 4/11/2016 | 17/6/2026 | In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0. | |
| Modificada | Media (6.1) | 3.4% | 💥 Exploit | Heat-trackr Project Heat-trackr | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin heat-trackr v1.0 | |
| Modificada | Alta (7.5) | 2.4% | — | Redhat OpenstackOpenstack Tripleo Heat Templates | 15/4/2016 | 17/6/2026 | The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private… | |
| Modificada | Alta (7.5) | 1.7% | — | Openstack Tripleo Heat Templates | 11/4/2016 | 17/6/2026 | The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter. | |
| Modificada | Crítica (9.8) | 1.9% | — | Ephiphanyheathdata Cardio Server | 27/12/2015 | 17/6/2026 | The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Labsmedia Clickheat | 18/6/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php. | |
| Modificada | Media (6.8) | 0.61% | — | Viralheat Argyle Social | 1/1/2015 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Argyle Social 2011-04-26 allow remote attackers to hijack the authentication of administrators for requests that (1) modify credentials via the role parameter to users/create/, (2) modify rules via the terms field in stream_filter_rule JSON data to… | |
| Modificada | Baja (3.5) | 1.6% | — | Openstack Heat | 23/5/2014 | 17/6/2026 | OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list. | |
| Modificada | Media (4) | 1.7% | — | Openstack Heat | 14/12/2013 | 17/6/2026 | The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path. | |
| Modificada | Media (4) | 1.0% | — | Openstack Heat | 14/12/2013 | 17/6/2026 | The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Frontrange Heat | 9/10/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Scripts-for-sites EZ Gaming Cheats | 23/2/2009 | 16/6/2026 | SQL injection vulnerability in view_reviews.php in Scripts for Sites (SFS) EZ Gaming Cheats allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Heathcosoft MP3 Trackmaker | 20/1/2009 | 16/6/2026 | Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file. |