Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 41% | 💥 Exploit | Klogserver Klog Server | 26/1/2021 | 17/6/2026 | KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter. | |
| Modificada | Crítica (9.8) | 88% | 💥 Exploit | Klogserver Klog Server | 27/12/2020 | 17/6/2026 | KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter. | |
| Modificada | Media (5.3) | 0.61% | — | Jenkins Logstash | 9/3/2020 | 17/6/2026 | Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Alta (7.5) | 2.1% | — | Elastic Logstash | 30/10/2019 | 17/6/2026 | Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop responding. | |
| Modificada | Alta (7.5) | 2.4% | — | Emca Energy Logserver | 5/8/2019 | 17/6/2026 | The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins AWS Cloudwatch Logs Publisher | 4/4/2019 | 17/6/2026 | Jenkins AWS CloudWatch Logs Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Crítica (9.8) | 2.4% | — | Elastic LogstashNetapp Active IQ Performance Analytics Services | 25/3/2019 | 17/6/2026 | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message. | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | IP History Logs Project IP History Logs | 28/1/2019 | 17/6/2026 | An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_logs.php useragent field. | |
| Modificada | Media (6.1) | 0.89% | — | Elasticsearch X-packElastic Kibana X-packElastic Logstash X-pack | 19/9/2018 | 17/6/2026 | X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or… | |
| Modificada | Media (5.4) | 0.65% | — | Elasticsearch X-packElastic Kibana X-packElastic Logstash X-pack | 19/9/2018 | 17/6/2026 | X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from or perform destructive actions on behalf… | |
| Modificada | Media (6.5) | 1.0% | — | Elastic Logstash | 30/3/2018 | 17/6/2026 | When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information. | |
| Modificada | Alta (7.8) | 0.35% | — | Elasticsearch Logstash | 25/9/2017 | 17/6/2026 | The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link. | |
| Modificada | Media (5.9) | 1.2% | — | Elastic LogstashElasticsearch Logstash | 9/8/2017 | 17/6/2026 | Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack. | |
| Modificada | Alta (7.5) | 2.5% | — | Elastic LogstashElasticsearch Logstash | 27/6/2017 | 17/6/2026 | Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server. | |
| Modificada | Alta (7.5) | 1.5% | — | Elastic Logstash | 16/6/2017 | 17/6/2026 | Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash… | |
| Modificada | Alta (7.5) | 1.1% | — | Elastic Logstash | 16/6/2017 | 17/6/2026 | Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data. | |
| Modificada | Alta (7.5) | 1.8% | — | Elastic Logstash | 16/6/2017 | 17/6/2026 | Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information. | |
| Modificada | Media (6.4) | 3.0% | — | Elastic Logstash | 15/6/2015 | 17/6/2026 | Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary files via vectors related to dynamic field references in the path option. | |
| Modificada | Media (4.3) | 1.1% | — | IPA Ilogscanner | 15/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IPA iLogScanner 4.0 allows remote attackers to inject arbitrary web script or HTML by triggering a crafted entry in a log file. | |
| Modificada | Alta (7.2) | 0.84% | 💥 Exploit | IBM Monitoring Agent FOR Unix LogsIBM Monitoring Server (ms) AND Shared Libraries (ax) | 29/8/2014 | 16/6/2026 | Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow… | |
| Modificada | Alta (7.5) | 3.3% | — | Elastic Logstash | 22/7/2014 | 17/6/2026 | Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/. | |
| Modificada | Media (4.3) | 1.6% | — | Blogstand Banner Plugin Project Blogstand-smart-banner | 10/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Blogstand Banner (blogstand-smart-banner) plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bs_blog_id parameter to wp-admin/options-general.php. | |
| Modificada | Media (4.3) | 1.6% | — | WP Microblogs Project WP Microblogs | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in get.php in the WP Microblogs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the oauth_verifier parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | John GEO Blogs Manager | 23/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php,… | |
| Modificada | Alta (7.5) | 2.1% | — | Drusus LogsurferKerry Thompson Logsurfer+ | 27/1/2012 | 16/6/2026 | Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote attackers to execute arbitrary commands via crafted strings in a log file. |