Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
340 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.25% | — | Joomla! | 20/8/2024 | 17/6/2026 | Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.. | |
| Modificada | Media (6.1) | 0.46% | — | Joomla! | 9/7/2024 | 17/6/2026 | The wrapper extensions do not correctly validate inputs, leading to XSS vectors. | |
| Modificada | Media (6.1) | 0.45% | — | Joomla! | 9/7/2024 | 17/6/2026 | The Custom Fields component not correctly filter inputs, leading to a XSS vector. | |
| Modificada | Media (6.1) | 0.44% | — | Joomla! | 9/7/2024 | 17/6/2026 | Improper handling of input could lead to an XSS vector in the StringHelper::truncate method. | |
| Modificada | Media (5.4) | 0.42% | — | Joomla! | 9/7/2024 | 17/6/2026 | The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. | |
| Modificada | Media (6.1) | 0.44% | — | Joomla! | 9/7/2024 | 17/6/2026 | Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field. | |
| Analizada | Media (6.5) | 49% | — | Joomla! | 29/2/2024 | 17/6/2026 | Inadequate content filtering leads to XSS vulnerabilities in various components. | |
| Analizada | Media (6.1) | 32% | — | Joomla! | 29/2/2024 | 17/6/2026 | Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. | |
| Modificada | Media (6.1) | 0.51% | — | Joomla! | 29/2/2024 | 17/6/2026 | Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions. | |
| Analizada | Media (4.3) | 0.54% | — | Joomla! | 29/2/2024 | 17/6/2026 | Inadequate parsing of URLs could result into an open redirect. | |
| Analizada | Media (6.3) | 0.51% | — | Joomla! | 29/2/2024 | 17/6/2026 | The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified. | |
| Modificada | Alta (7.5) | 0.81% | 💥 PoC | Joomla! | 29/11/2023 | 17/6/2026 | The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information. | |
| Modificada | Alta (7.5) | 0.56% | — | Joomla! | 30/5/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods. | |
| Modificada | Media (6.1) | 0.41% | — | Joomla! | 30/5/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen. | |
| Analizada | Media (5.3) | 100% | ⚠ Explotación activa💥 Exploit | Joomla! | 16/2/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | |
| Modificada | Media (4.3) | 0.44% | — | Joomla! | 1/2/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs. | |
| Modificada | Media (6.3) | 0.23% | — | Joomla! | 1/2/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages. | |
| Modificada | Media (6.1) | 0.48% | — | Joomla! | 8/11/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media. | |
| Modificada | Media (6.1) | 0.40% | 💥 PoC | Joomla! | 25/10/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components. | |
| Modificada | Media (5.3) | 0.56% | — | Joomla! | 25/10/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests. | |
| Modificada | Media (5.3) | 0.59% | — | Joomla! | 31/8/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes. | |
| Modificada | Media (6.1) | 0.59% | — | Joomla! | 30/3/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media. | |
| Modificada | Media (6.1) | 0.67% | — | Joomla! | 30/3/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. | |
| Modificada | Crítica (9.8) | 1.2% | — | Joomla! | 30/3/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data. | |
| Modificada | Media (6.1) | 0.59% | — | Joomla! | 30/3/2022 | 17/6/2026 | An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not. |