Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.86% | — | Vtiger CRM | 27/9/2022 | 17/6/2026 | Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules. | |
| Modificada | Alta (8.8) | 1.2% | — | Tigergraph | 5/9/2022 | 17/6/2026 | The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can execute arbitrary C++ code. NOTE: the vendor's position is "GSQL was behaving as expected." | |
| Modificada | Media (5.3) | 0.95% | — | Presstigers Simple JOB Board | 22/8/2022 | 17/6/2026 | The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing of uploaded resumes in certain configurations. | |
| Analizada | Media (5.5) | 0.61% | — | Tigera CalicoTigera Calico Enterprise | 6/6/2022 | 17/6/2026 | Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficient validation, a privileged attacker may be able to set a floating IP annotation to a pod even if the feature is not enabled. This may… | |
| Modificada | Media (5.4) | 0.57% | — | Presstigers Simple Event Planner | 25/3/2022 | 17/6/2026 | Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parameters: &custom[event_organiser], &custom[organiser_email], &custom[organiser_contact]. | |
| Modificada | Media (5.4) | 0.57% | — | Presstigers Simple Event Planner | 25/3/2022 | 17/6/2026 | Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg][]. | |
| Modificada | Media (4.8) | 0.92% | — | Presstigers Simple JOB Board | 21/10/2021 | 17/6/2026 | The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-settings-privacy.php file which allowed attackers with administrative user access to inject… | |
| Modificada | Crítica (9.8) | 1.3% | — | Vtiger CRM | 29/4/2021 | 17/6/2026 | An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. | |
| Modificada | Media (6.5) | 3.6% | 💥 Exploit | Vtiger CRM | 20/1/2021 | 17/6/2026 | Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories. | |
| Modificada | Media (6.1) | 0.75% | — | Vtiger CRM | 20/1/2021 | 17/6/2026 | Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. | |
| Modificada | Alta (7.7) | 30% | 💥 Exploit | Presstigers Simple Board JOB | 15/1/2021 | 17/6/2026 | Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php. | |
| Modificada | Alta (8.1) | 3.1% | — | TigervncDebian LinuxOpensuse Leap | 27/9/2020 | 17/6/2026 | In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception. | |
| Modificada | Alta (8.8) | 43% | 💥 Exploit | Vtiger CRM | 7/2/2020 | 16/6/2026 | vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 40% | 💥 Exploit | Vtiger CRM | 6/2/2020 | 17/6/2026 | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a… | |
| Modificada | Crítica (9.8) | 69% | 💥 Exploit | Vtiger CRM | 29/1/2020 | 16/6/2026 | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Vtiger CRM | 28/1/2020 | 16/6/2026 | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'. | |
| Modificada | Alta (8.1) | 7.5% | 💥 Exploit | Vtiger CRM | 28/1/2020 | 16/6/2026 | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code. | |
| Modificada | Crítica (9.8) | 2.5% | — | Tigervnc | 2/1/2020 | 17/6/2026 | Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering. | |
| Modificada | Alta (7.2) | 4.5% | — | TigervncOpensuse Leap | 26/12/2019 | 17/6/2026 | TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability occurs due to insufficient sanitization of PixelFormat. Since remote attacker can choose offset from start of the buffer to start writing his values, exploitation of this… | |
| Modificada | Alta (7.2) | 4.5% | — | TigervncOpensuse Leap | 26/12/2019 | 17/6/2026 | TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in processing MemOutStream. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be… | |
| Modificada | Alta (7.2) | 4.3% | — | Tigervnc | 26/12/2019 | 17/6/2026 | TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity. | |
| Modificada | Alta (7.2) | 4.8% | — | TigervncOpensuse Leap | 26/12/2019 | 17/6/2026 | TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDecoder due to incorrect value checks. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity. | |
| Modificada | Alta (7.2) | 4.7% | — | TigervncOpensuse Leap | 26/12/2019 | 17/6/2026 | TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception, ZRLEDecoder may try to access stack variable, which has been already freed during the process of stack unwinding. Exploitation of… | |
| Modificada | Alta (8.8) | 1.0% | — | Vtiger CRM | 21/11/2019 | 17/6/2026 | In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request. | |
| Modificada | Media (6.1) | 0.92% | — | Presstigers Simple JOB Board | 13/8/2019 | 17/6/2026 | The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search. |