Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.81%—Softvibe Saraban18/1/202217/6/2026
SoftVibe SARABAN for INFOMA 1.1 is vulnerable to stored cross-site scripting (XSS) that allows users to store scripts in certain fields (e.g. subject, description) of the document form.
ModificadaAlta (7.5)1.5%—Softvibe Saraban18/1/202217/6/2026
SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.
ModificadaMedia (6.5)0.55%—Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs8/11/202117/6/2026
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack
ModificadaAlta (7.5)2.2%—Rakuten Viber22/6/202017/6/2026
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either relay the request or capture the hash for offline password cracking. NOTE: this issue exists because of…
ModificadaMedia (5.4)0.81%—Microfocus Vibe25/3/202017/6/2026
A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker controlled JavaScript will execute in…
ModificadaMedia (5.5)0.38%—Rakuten Viber13/2/202017/6/2026
An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats' functionality allows a user to delete all traces of a chat either by using a time trigger or by direct request. There is a bug in this functionality which leaves behind…
ModificadaAlta (8.8)1.7%—Rakuten Viber6/11/201917/6/2026
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victim's device contains cleartext information such as the device model and OS version, IMSI, and 20…
ModificadaAlta (7.8)15%—Rakuten Viber3/6/201917/6/2026
A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An attacker could exploit this vulnerability by convincing a targeted user to follow a malicious link.…
ModificadaMedia (6.5)0.53%—Multidots ADD Social Share Messenger Buttons Whatsapp AND Viber31/5/201817/6/2026
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings via wp-admin/admin-post.php…
ModificadaAlta (7.5)0.84%—Vibease ChatVibease Wireless Remote Vibrator1/12/201717/6/2026
The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages with other apps and the PLAIN SASL mechanism to send auth tokens to Vibease servers, which allows remote attackers to obtain user credentials, messages, and other sensitive information by sniffing…
ModificadaMedia (6.5)1.4%—Micro Focus Vibe18/5/201717/6/2026
An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is…
ModificadaMedia (5.4)1.9%💥 ExploitPhpvibe26/8/201617/6/2026
Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment.
ModificadaAlta (10)6.0%—Novell Vibe Onprem9/3/201116/6/2026
Unspecified vulnerability in Novell Vibe OnPrem 3.0 before Hot Patch 1 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaBaja (3.5)0.77%—Novell Vibe Onprem7/1/201116/6/2026
Cross-site scripting (XSS) vulnerability in gwtTeaming.rpc in Novell Vibe OnPrem 3 BETA allows remote authenticated users to inject arbitrary web script or HTML via the Micro Blog (aka What Are You Working On?) field.
ModificadaAlta (9.3)2.8%💥 ExploitMixvibes27/10/200916/6/2026
Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.
ModificadaAlta (7.5)3.4%—Vibechild Directory Manager5/9/200116/6/2026
edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function.
Orbitaley — Vulnerabilidades