Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | — | PloneRedhat CongaRedhat Luci | 3/2/2011 | 16/6/2026 | Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors. | |
| Modificada | Media (6.4) | 2.0% | — | Redhat Luci | 6/11/2010 | 16/6/2026 | The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Solucija Snews | 30/7/2010 | 16/6/2026 | SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Pantha Translucid | 22/6/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject… | |
| Modificada | Media (4.3) | 1.3% | — | Solucija Snews | 28/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. | |
| Modificada | Media (6.8) | 1.7% | — | Lucid Designs Lucid Calendar | 15/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Lucidcms | 6/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the command parameter. | |
| Modificada | Media (5) | 1.3% | — | Lucidcms | 6/4/2006 | 16/6/2026 | LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Solucija Snews | 15/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field. | |
| Modificada | Alta (7.5) | 1.3% | — | Solucija Snews | 15/2/2006 | 16/6/2026 | SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Solucija Snews | 27/11/2005 | 16/6/2026 | SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Lucidcms | 4/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Lucidcms | 4/10/2005 | 16/6/2026 | SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field. |