Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.4% | — | Openresty Lua-nginx-module | 6/4/2021 | 17/6/2026 | ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header. | |
| Modificada | Media (4.8) | 0.59% | — | Employee Performance Evaluation System Project Employee Performance Evaluation System | 20/1/2021 | 17/6/2026 | Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields. | |
| Modificada | Media (4.8) | 0.55% | — | Employee Performance Evaluation System Project Employee Performance Evaluation System | 20/1/2021 | 17/6/2026 | Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields. | |
| Modificada | Alta (7.5) | 1.5% | — | Luajit | 17/8/2020 | 17/6/2026 | LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c. | |
| Modificada | Media (5.3) | 1.7% | — | LUA | 17/8/2020 | 17/6/2026 | lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage. | |
| Analizada | Media (5.3) | 3.8% | — | LUAFedoraproject FedoraDebian Linux | 17/8/2020 | 17/6/2026 | ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31). | |
| Modificada | Alta (7.5) | 1.7% | — | LUA | 17/8/2020 | 17/6/2026 | ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference. | |
| Modificada | Alta (7.8) | 1.1% | — | LUAFedoraproject Fedora | 13/8/2020 | 17/6/2026 | Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row. | |
| Modificada | Media (5.5) | 0.55% | — | LUA | 24/7/2020 | 17/6/2026 | Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function. | |
| Modificada | Alta (7.5) | 3.2% | — | LuajitDebian LinuxCanonical Ubuntu Linux | 21/7/2020 | 17/6/2026 | LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled. | |
| Modificada | Crítica (9.8) | 2.2% | — | LUA | 21/7/2020 | 17/6/2026 | Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members. | |
| Modificada | Alta (8.8) | 2.4% | — | LUA | 21/7/2020 | 17/6/2026 | Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free. | |
| Modificada | Media (6.1) | 99% | — | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Alta (7.1) | 1.1% | — | Oracle Financial Services Hedge Management AND Ifrs Valuations | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Crítica (9.1) | 0.84% | — | Lua-openssl Project Lua-openssl | 27/2/2020 | 17/6/2026 | openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. | |
| Modificada | Crítica (9.1) | 0.84% | — | Lua-openssl Project Lua-openssl | 27/2/2020 | 17/6/2026 | openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. | |
| Modificada | Crítica (9.1) | 0.84% | — | Lua-openssl Project Lua-openssl | 27/2/2020 | 17/6/2026 | openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. | |
| Modificada | Media (6.1) | 1.6% | — | Keplerproject Cgilua | 6/2/2020 | 17/6/2026 | The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NOTE: CVE-2014-10399 and CVE-2014-10400 were SPLIT from this ID. | |
| Modificada | Media (6.1) | 1.2% | — | Keplerproject Cgilua | 6/2/2020 | 17/6/2026 | The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875. | |
| Modificada | Media (6.1) | 1.3% | — | Keplerproject Cgilua | 6/2/2020 | 17/6/2026 | The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875. | |
| Modificada | Crítica (9.1) | 1.4% | — | LuajitMoonjit Project Moonjit | 29/11/2019 | 17/6/2026 | In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations, because certain cases involving valid stack levels and > options are mishandled. NOTE: The LuaJIT project owner states that the debug libary is… | |
| Modificada | Crítica (9.8) | 2.3% | — | Open Faculty Evaluation System Project Open Faculty Evaluation System | 19/6/2019 | 17/6/2026 | Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757. | |
| Modificada | Crítica (9.8) | 2.3% | — | Open Faculty Evaluation System Project Open Faculty Evaluation System | 19/6/2019 | 17/6/2026 | Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758. | |
| Modificada | Media (6.1) | 87% | — | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.5) | 17% | — | LUACanonical Ubuntu Linux | 23/1/2019 | 17/6/2026 | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships. |