Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.2%—PloneRedhat CongaRedhat Luci3/2/201116/6/2026
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.
ModificadaMedia (6.4)2.0%—Redhat Luci6/11/201016/6/2026
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.
ModificadaAlta (7.5)0.91%💥 ExploitSolucija Snews30/7/201016/6/2026
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.
ModificadaMedia (4.3)1.6%💥 ExploitPantha Translucid22/6/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject…
ModificadaMedia (4.3)1.3%—Solucija Snews28/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
ModificadaMedia (6.8)1.7%—Lucid Designs Lucid Calendar15/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (4.3)1.7%💥 ExploitLucidcms6/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the command parameter.
ModificadaMedia (5)1.3%—Lucidcms6/4/200616/6/2026
LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message.
ModificadaMedia (4.3)1.8%💥 ExploitSolucija Snews15/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
ModificadaAlta (7.5)1.3%—Solucija Snews15/2/200616/6/2026
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
ModificadaAlta (7.5)1.1%💥 ExploitSolucija Snews27/11/200516/6/2026
SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.
ModificadaMedia (4.3)1.8%💥 ExploitLucidcms4/10/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.
ModificadaAlta (7.5)1.1%💥 ExploitLucidcms4/10/200516/6/2026
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.
Orbitaley — Vulnerabilidades