Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 2.0% | 💥 PoC | Node-pdf-generator Project Node-pdf-generator | 6/10/2020 | 17/6/2026 | This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack. | |
| Modificada | Alta (8.8) | 1.3% | — | Istio-operator Project Istio-operator | 16/9/2020 | 17/6/2026 | An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions through 1.1.3. This flaw allows an attacker with a basic level of access to the cluster to deploy a custom gateway/pod to any namespace, potentially gaining access to privileged service account tokens.… | |
| Modificada | Crítica (9.8) | 2.5% | — | Json Pattern Validator Project Json Pattern Validator | 10/8/2020 | 17/6/2026 | jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array. | |
| Modificada | Crítica (9.8) | 2.2% | — | HT Editor Project HT Editor | 23/1/2020 | 16/6/2026 | HT Editor 2.0.20 has a Remote Stack Buffer Overflow Vulnerability | |
| Modificada | Crítica (9.8) | 1.4% | — | Schema-inspector Project Schema-inspector | 22/1/2020 | 17/6/2026 | In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector. | |
| Modificada | Alta (7) | 0.25% | — | Squid Analysis Report Generator Project Squid Analysis Report GeneratorOpensuse Backports SLEOpensuse Leap | 21/1/2020 | 17/6/2026 | log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create the directory, and place symlinks in it… | |
| Modificada | Media (5.3) | 0.97% | — | Json Pattern Validator Project Json Pattern Validator | 2/12/2019 | 17/6/2026 | In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the… | |
| Modificada | Crítica (9.8) | 57% | 💥 Exploit | Exhibitor Project Exhibitor | 13/11/2019 | 17/6/2026 | An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any… | |
| Modificada | Crítica (9.8) | 2.0% | — | Typestack Class-validator Project Typestack Class-validator | 24/10/2019 | 17/6/2026 | In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most… | |
| Modificada | Media (6.1) | 0.93% | — | WP Editor Project WP Editor | 12/8/2019 | 17/6/2026 | The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues. | |
| Modificada | Alta (7.5) | 1.5% | — | Metadataextractor Project Metadataextractor | 25/7/2019 | 17/6/2026 | MetadataExtractor 2.1.0 allows stack consumption. | |
| Modificada | Media (6.1) | 1.2% | — | Hexoeditor Project Hexoeditor | 15/7/2019 | 17/6/2026 | HexoEditor v1.1.8-beta is affected by: XSS to code execution. | |
| Modificada | Alta (7.5) | 2.8% | — | Http-live-simulator Project Http-live-simulator | 3/4/2019 | 17/6/2026 | Path traversal vulnerability in http-live-simulator npm package version 1.0.5 allows arbitrary path to be accessed on the file system by a remote attacker. | |
| Modificada | Media (5.5) | 0.96% | — | Boolector Project Boolector | 7/2/2019 | 17/6/2026 | In parser/btorsmt2.c in Boolector 3.0.0, opening a specially crafted input file leads to a use after free in get_failed_assumptions or btor_delete. | |
| Modificada | Alta (7.5) | 1.7% | — | Http-live-simulator Project Http-live-simulator | 1/2/2019 | 17/6/2026 | Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appending extra slashes after the URL. | |
| Modificada | Media (5) | 0.43% | — | Sos-collector Project Sos-collectorRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+2 | 27/9/2018 | 17/6/2026 | It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory. | |
| Modificada | Alta (8.8) | 77% | 💥 Exploit | Plainview Activity Monitor Project Plainview Activity Monitor | 26/8/2018 | 17/6/2026 | The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter of a wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_tools request. | |
| Modificada | Media (6.1) | 0.94% | — | Angular Redactor Project Angular Redactor | 5/7/2018 | 17/6/2026 | Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035. | |
| Modificada | Media (6.1) | 1.1% | — | Html-janitor Project Html-janitor | 4/6/2018 | 17/6/2026 | html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled values. | |
| Modificada | Alta (7.5) | 1.4% | — | Negotiator Project Negotiator | 31/5/2018 | 17/6/2026 | negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string. | |
| Modificada | Alta (8.1) | 1.7% | — | Product-monitor Project Product-monitor | 29/5/2018 | 17/6/2026 | product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all the information about the status of a product, including live monitoring, statistics, endpoints, and test results into one place. product-monitor versions below 2.2.5 download JavaScript resources… | |
| Modificada | Media (4.8) | 1.8% | 💥 Exploit | Tagregator Project Tagregator | 5/5/2018 | 17/6/2026 | The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action. | |
| Modificada | Alta (7.5) | 1.2% | — | Photo,video Locker-calculator Project Photo,video Locker-calculator | 20/2/2018 | 17/6/2026 | smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to access files via the backdoor 17621762 PIN. | |
| Modificada | Alta (7.5) | 0.64% | — | Photo,video Locker-calculator Project Photo,video Locker-calculator | 20/2/2018 | 17/6/2026 | The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" command. | |
| Modificada | Media (5.4) | 1.0% | — | Simple Download Monitor Project Simple Download Monitor | 4/1/2018 | 17/6/2026 | The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php. |