Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.4%—Openresty Lua-nginx-module6/4/202117/6/2026
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
ModificadaMedia (4.8)0.59%—Employee Performance Evaluation System Project Employee Performance Evaluation System20/1/202117/6/2026
Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields.
ModificadaMedia (4.8)0.55%—Employee Performance Evaluation System Project Employee Performance Evaluation System20/1/202117/6/2026
Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields.
ModificadaAlta (7.5)1.5%—Luajit17/8/202017/6/2026
LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.
ModificadaMedia (5.3)1.7%—LUA17/8/202017/6/2026
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.
AnalizadaMedia (5.3)3.8%—LUAFedoraproject FedoraDebian Linux17/8/202017/6/2026
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
ModificadaAlta (7.5)1.7%—LUA17/8/202017/6/2026
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.
ModificadaAlta (7.8)1.1%—LUAFedoraproject Fedora13/8/202017/6/2026
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
ModificadaMedia (5.5)0.55%—LUA24/7/202017/6/2026
Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function.
ModificadaAlta (7.5)3.2%—LuajitDebian LinuxCanonical Ubuntu Linux21/7/202017/6/2026
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
ModificadaCrítica (9.8)2.2%—LUA21/7/202017/6/2026
Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.
ModificadaAlta (8.8)2.4%—LUA21/7/202017/6/2026
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
ModificadaMedia (6.1)99%—JqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaAlta (7.1)1.1%—Oracle Financial Services Hedge Management AND Ifrs Valuations15/4/202017/6/2026
Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModificadaCrítica (9.1)0.84%—Lua-openssl Project Lua-openssl27/2/202017/6/2026
openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
ModificadaCrítica (9.1)0.84%—Lua-openssl Project Lua-openssl27/2/202017/6/2026
openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
ModificadaCrítica (9.1)0.84%—Lua-openssl Project Lua-openssl27/2/202017/6/2026
openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
ModificadaMedia (6.1)1.6%—Keplerproject Cgilua6/2/202017/6/2026
The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NOTE: CVE-2014-10399 and CVE-2014-10400 were SPLIT from this ID.
ModificadaMedia (6.1)1.2%—Keplerproject Cgilua6/2/202017/6/2026
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
ModificadaMedia (6.1)1.3%—Keplerproject Cgilua6/2/202017/6/2026
The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
ModificadaCrítica (9.1)1.4%—LuajitMoonjit Project Moonjit29/11/201917/6/2026
In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations, because certain cases involving valid stack levels and > options are mishandled. NOTE: The LuaJIT project owner states that the debug libary is…
ModificadaCrítica (9.8)2.3%—Open Faculty Evaluation System Project Open Faculty Evaluation System19/6/201917/6/2026
Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.
ModificadaCrítica (9.8)2.3%—Open Faculty Evaluation System Project Open Faculty Evaluation System19/6/201917/6/2026
Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758.
ModificadaMedia (6.1)87%—JqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (7.5)17%—LUACanonical Ubuntu Linux23/1/201917/6/2026
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.