Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.98% | — | Linuxfoundation Vitess | 11/5/2023 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that from that point on, anyone who tries to create a new shard from VTAdmin will… | |
| Modificada | Baja (2.7) | 0.78% | — | Linuxfoundation Vitess | 14/4/2023 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing `/` characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list all the keyspaces using `vtctldclient… | |
| Modificada | Alta (8.6) | 0.76% | — | Gravitee API Management | 3/1/2023 | 17/6/2026 | Gravitee API Management before 3.15.13 allows path traversal through HTML injection. | |
| Modificada | Media (6.1) | 0.71% | — | Gravitee API Management | 23/8/2022 | 17/6/2026 | HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request. | |
| Modificada | Media (4.3) | 1.3% | — | Vitejs Vite | 18/8/2022 | 17/6/2026 | Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service. | |
| Modificada | Crítica (9.8) | 1.7% | — | Vitec Exterity AvediaserverVitec Exterity Avediastream Encoders FirmwareVitec Avediastream M9605 FirmwareVitec Avediastream M9400 Firmware+6 | 8/10/2021 | 17/6/2026 | VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root. | |
| Modificada | Media (6.1) | 0.82% | — | Invitebox | 10/9/2021 | 17/6/2026 | The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.1. | |
| Modificada | Alta (7.5) | 1.3% | — | Invite Anyone Project Invite Anyone | 16/8/2019 | 17/6/2026 | The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input. | |
| Modificada | Alta (8.8) | 0.65% | — | Invite Anyone Project Invite Anyone | 16/8/2019 | 17/6/2026 | The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF. | |
| Modificada | Crítica (9.8) | 1.8% | — | Invite Anyone Project Invite Anyone | 16/8/2019 | 17/6/2026 | The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations. | |
| Modificada | Alta (7.5) | 1.1% | — | Vitemoneycoin Project Vitemoneycoin | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for ViteMoneyCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Techjoomla Invitex | 17/2/2018 | 17/6/2026 | SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action. | |
| Modificada | Alta (7.4) | 1.5% | — | Savitech-ic Savitech Driver | 10/11/2017 | 17/6/2026 | Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Authorities store, aka "Inaudible Subversion." | |
| Modificada | Alta (8.2) | 2.3% | — | Envitech Envidas Ultimate | 17/10/2017 | 17/6/2026 | An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely. | |
| Modificada | Media (5.3) | 1.8% | — | Teleogistic Invite Anyone | 17/3/2017 | 17/6/2026 | An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack. | |
| Modificada | Baja (3.5) | 0.95% | — | Node Invite Project Node Invite | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title. | |
| Modificada | Media (5.8) | 1.2% | — | Node Invite Project Node Invite | 21/4/2015 | 17/6/2026 | Open redirect vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter. | |
| Modificada | Media (6.8) | 0.64% | — | Node Invite Project Node Invite | 21/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to hijack the authentication of users with the "node_invite_can_manage_invite" permission for requests that re-enable node invitations via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.84% | — | Drupal Asin Field ModuleDrupalDrupal E-commerce ModuleDrupal Fullname Field FOR CCK+6 | 22/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments… |