Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.97% | — | Serpico Project Serpico | 7/5/2020 | 17/6/2026 | An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve all of the attachments of all users (including administrators) from the database. | |
| Modificada | Crítica (9.8) | 4.4% | — | Apiconnect-cli-plugins Project Apiconnect-cli-plugins | 6/4/2020 | 17/6/2026 | apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument. | |
| Modificada | Media (5.3) | 0.80% | — | Serpico Project Serpico | 15/1/2020 | 17/6/2026 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The Add Collaborator allows unlimited data via the author parameter, even if the data does not match anything in the database. | |
| Modificada | Media (4.8) | 0.59% | — | Serpico Project Serpico | 15/1/2020 | 17/6/2026 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/add_user/UID allows stored XSS via the author parameter. | |
| Modificada | Media (6.5) | 0.86% | — | Serpico Project Serpico | 15/1/2020 | 17/6/2026 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin to enter an Old Password value on the Change Password screen does not… | |
| Modificada | Media (4.8) | 0.71% | — | Serpico Project Serpico | 15/1/2020 | 17/6/2026 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter. | |
| Modificada | Media (4.8) | 0.71% | — | Serpico Project Serpico | 15/1/2020 | 17/6/2026 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter. | |
| Modificada | Alta (8.8) | 0.48% | — | Serpico Project Serpico | 15/1/2020 | 17/6/2026 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it uses the Origin header (which must match the request origin). This is problematic in conjunction with XSS: one can escalate privileges from User level to Administrator. | |
| Modificada | Media (4.6) | 0.24% | — | Espressif Esp32-d0wd FirmwareEspressif Esp32-d2wd FirmwareEspressif Esp32-s0wd FirmwareEspressif Esp32-pico-d4 Firmware | 14/11/2019 | 17/6/2026 | An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by… | |
| Modificada | Alta (7.8) | 0.89% | — | Picoc Project Picoc | 13/9/2019 | 17/6/2026 | PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c. | |
| Modificada | Crítica (9.8) | 2.2% | — | Altran Picotcp | 17/11/2017 | 17/6/2026 | picoTCP (versions 1.7.0 - 1.5.0) is vulnerable to stack buffer overflow resulting in code execution or denial of service attack | |
| Modificada | Alta (7.8) | 0.63% | — | Epicor CRS Retail Store | 6/9/2017 | 17/6/2026 | The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injecting Javascript into the window source to create a button that spawns a command shell. | |
| Modificada | Crítica (9.8) | 2.2% | — | Picocom Project Picocom | 28/5/2017 | 17/6/2026 | picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely. | |
| Modificada | Media (5.3) | 3.5% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | |
| Modificada | Alta (7.3) | 4.2% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3… | |
| Modificada | Media (5) | 5.8% | 💥 Exploit | Epicor Enterprise | 4/11/2014 | 17/6/2026 | Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by reading HTML source code of the database connection and email settings page. | |
| Modificada | Alta (7.5) | 2.2% | — | Epicor Procurement | 10/10/2014 | 17/6/2026 | SQL injection vulnerability in Epicor Procurement before 7.4 SP2 allows remote attackers to execute arbitrary SQL commands via the User field. | |
| Modificada | Media (4.3) | 4.2% | 💥 Exploit | Epicor Enterprise | 10/10/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote attackers to inject arbitrary web script or HTML via the (1) Notes section to Order details; (2) Description section to "Order to consume"; (3) Favorites name section to Favorites; (4) FiltKeyword… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Picopublisher | 17/11/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php. | |
| Modificada | Alta (10) | 8.2% | 💥 Exploit | Picoflat CMS | 4/4/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagina parameter, a different vulnerability than CVE-2007-5390. | |
| Modificada | Media (6.8) | 2.3% | — | Picoflat CMS | 10/11/2007 | 16/6/2026 | index.php in Domenico Mancini PicoFlat CMS before 0.4.18 allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. NOTE: this can be leveraged to bypass authentication and upload files by including pico_insert.php or unspecified other administrative… | |
| Modificada | Media (6.8) | 4.4% | 💥 Exploit | Picoflat CMS | 12/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pagina parameter. | |
| Modificada | Alta (9.3) | 8.4% | 💥 Exploit | Yoggie PicoYoggie Pico PRO | 5/7/2007 | 16/6/2026 | Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences). | |
| Modificada | Alta (7.8) | 8.5% | 💥 Exploit | Picozip | 9/5/2007 | 16/6/2026 | PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. |