Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
118 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.89% | — | Dotnetfoundation C# Language Server Protocol | 17/7/2023 | 17/6/2026 | A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The manipulation leads to resource… | |
| Modificada | Crítica (9.8) | 0.51% | — | Ipandlanguageredirect Project Ipandlanguageredirect | 16/6/2023 | 17/6/2026 | The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection. | |
| Modificada | Media (6.1) | 0.55% | — | Multi Language Hotel Management Software Project Multi Language Hotel Management Software | 7/5/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Multi Language Hotel Management Software 1.0 and classified as problematic. This vulnerability affects unknown code of the file ajax.php of the component POST Parameter Handler. The manipulation of the argument complaint_type with the input… | |
| Modificada | Alta (8.8) | 0.76% | — | Snyk CLISnyk Language ServerSnyk Security | 30/11/2022 | 17/6/2026 | The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be executed with the privileges of the application. This vulnerability… | |
| Modificada | Crítica (9.8) | 0.78% | — | Multi Language Hotel Management Software Project Multi Language Hotel Management Software | 4/8/2022 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software. Affected is an unknown function. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.87% | — | Multi Language Hotel Management Software Project Multi Language Hotel Management Software | 4/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Multi Language Hotel Management Software. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument room_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (4.8) | 0.68% | — | Gtranslate Google Language Translator | 8/11/2021 | 17/6/2026 | The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.3) | 0.48% | — | Language BAR Flags Project Language BAR Flags | 13/9/2021 | 17/6/2026 | The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which… | |
| Modificada | Alta (8.8) | 1.4% | — | Eigentech Natural Language Processing | 7/9/2021 | 17/6/2026 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/ user creation endpoint allows a standard user to create a super user account with a defined password. This directly leads to privilege escalation. | |
| Modificada | Alta (8.8) | 1.3% | — | Eigentech Natural Language Processing | 7/9/2021 | 17/6/2026 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more. | |
| Modificada | Alta (8.1) | 0.95% | — | Eigentech Natural Language Processing | 7/9/2021 | 17/6/2026 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/sso/config/ SSO configuration endpoint allows any logged-in user (guest, standard, or admin) to view and modify information. | |
| Modificada | Media (5.3) | 2.1% | — | Eclipse Jakarta Expression LanguageQuarkusOracle Communications Cloud Native Core PolicyOracle Weblogic Server | 26/5/2021 | 17/6/2026 | In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. | |
| Modificada | Alta (7.8) | 2.1% | — | Prisma Language-tools | 29/4/2021 | 17/6/2026 | Prisma VS Code a VSCode extension for Prisma schema files. This is a Remote Code Execution Vulnerability that affects all versions of the Prisma VS Code extension older than 2.20.0. If a custom binary path for the Prisma format binary is set in VS Code Settings, for example by downloading a project that has a… | |
| Modificada | Alta (7.8) | 3.3% | — | Redhat Language Support FOR Java | 10/12/2020 | 17/6/2026 | Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 8.9% | — | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Alta (8.1) | 2.1% | — | Gurux Device Language Message Specification Director | 25/2/2020 | 17/6/2026 | An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path traversal. This allows the attacker exploiting CVE-2020-8809 to send executable files and place them in an autorun… | |
| Modificada | Alta (8.1) | 1.0% | — | Gurux Device Language Message Specification Director | 25/2/2020 | 17/6/2026 | Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by modifying the contents of gurux.fi/obis/files.xml and gurux.fi/updates/updates.xml. Then, the attacker can modify the… | |
| Modificada | Alta (8) | 0.96% | — | Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+1 | 17/12/2019 | 17/6/2026 | The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains a vulnerability that theoretically allows an attacker with permission to write… | |
| Modificada | Alta (8.8) | 2.0% | — | XML Language Server Project XML Server ProjectEclipse Wild WEB DeveloperTheia XML Extension Project Theia XML Extension | 23/10/2019 | 17/6/2026 | XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response capture for password… | |
| Modificada | Media (6.5) | 2.8% | — | XML Language Server Project XML Server ProjectEclipse Wild WEB DeveloperTheia XML Extension Project Theia XML Extension | 23/10/2019 | 17/6/2026 | XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal. | |
| Modificada | Media (6.1) | 0.95% | — | Gtranslate Google Language Translator | 13/8/2019 | 17/6/2026 | The google-language-translator plugin before 5.0.06 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tibco Spotfire AnalystTibco Spotfire ClientTibco Spotfire ConnectorsTibco Spotfire Deployment KIT+3 | 24/7/2018 | 17/6/2026 | Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in… | |
| Modificada | Media (5.4) | 0.61% | — | Tibco Silver Fabric Enabler FOR Spotfire WEB PlayerTibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Automation Services+6 | 24/7/2018 | 17/6/2026 | Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the… | |
| Modificada | Alta (8.8) | 0.93% | — | Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+1 | 27/6/2018 | 17/6/2026 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may… | |
| Modificada | Crítica (9.8) | 3.2% | — | Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+1 | 27/6/2018 | 17/6/2026 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may… |