Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
175 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.79% | — | Ecommerce Codeigniter Bootstrap Project Ecommerce Codeigniter Bootstrap | 8/4/2022 | 17/6/2026 | Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php. | |
| Modificada | Media (5.4) | 0.72% | — | Tastyigniter | 5/4/2022 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository tastyigniter/tastyigniter prior to 3.3.0. | |
| Modificada | Crítica (9.8) | 21% | 💥 Exploit | Pascom Cloud Phone SystemIgniterealtime Openfire | 18/3/2022 | 17/6/2026 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints. | |
| Modificada | Alta (8.8) | 0.56% | — | Codeigniter | 28/2/2022 | 17/6/2026 | CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attackers to bypass the CodeIgniter4 Cross-Site Request Forgery (CSRF) protection mechanism. Users should upgrade to version 4.1.9. There are workarounds for this vulnerability,… | |
| Modificada | Crítica (9.8) | 1.2% | — | Codeigniter | 28/2/2022 | 17/6/2026 | CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for this vulnerability. | |
| Modificada | Media (5.4) | 1.1% | 💥 PoC | Tastyigniter | 9/2/2022 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists within the 3.2.2 version of TastyIgniter. The "items%5B0%5D%5Bpath%5D" parameter of a request made to /admin/allergens/edit/1 is vulnerable. | |
| Modificada | Media (6.1) | 1.0% | — | Codeigniter | 24/1/2022 | 17/6/2026 | CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseTrait` in Codeigniter4 prior to version 4.1.8. Attackers can do XSS attacks if a potential victim is using `API\ResponseTrait`. Version 4.1.8 contains a patch for this… | |
| Modificada | Crítica (9.8) | 38% | — | Codeigniter | 4/1/2022 | 17/6/2026 | CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulnerability, and possibly execute existing PHP code on the server. We are aware of a working exploit,… | |
| Modificada | Media (6.1) | 0.84% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter. | |
| Modificada | Media (5.4) | 8.0% | 💥 PoC | Tastyigniter | 15/8/2021 | 17/6/2026 | TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs. | |
| Modificada | Alta (8.8) | 0.93% | — | Ignitedcms | 6/8/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component "/admin/profile/save_profile". | |
| Modificada | Baja (2.7) | 4.2% | — | Eclipse JettyFedoraproject FedoraApache IgniteApache Solr+19 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory. | |
| Modificada | Media (5.4) | 0.74% | — | Igniterealtime Openfire | 12/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS. | |
| Modificada | Media (5.4) | 0.74% | — | Igniterealtime Openfire | 12/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS. | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 12/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS. | |
| Modificada | Media (5.4) | 0.62% | — | Igniterealtime Openfire | 12/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS. | |
| Modificada | Media (5.4) | 0.57% | — | Igniterealtime Openfire | 11/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS. | |
| Modificada | Media (5.4) | 0.36% | — | Ignitenet Helios Glinq | 23/9/2020 | 17/6/2026 | In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms. | |
| Modificada | Media (6.5) | 0.99% | — | Ignitenet Helios Glinq | 23/9/2020 | 17/6/2026 | In IgniteNet HeliOS GLinq v2.2.1 r2961, if a user logs in and sets the ‘wan_type’ parameter, the wan interface for the device will become unreachable, which results in a denial of service condition for devices dependent on this connection. | |
| Modificada | Media (4.3) | 0.90% | — | Ignitenet Helios Glinq | 23/9/2020 | 17/6/2026 | In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/config/luci) by the authenticator.htmlauth function. When modified with arbitrary javascript, this causes a denial-of-service condition for all other users. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php. |