Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

94 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.98%—Linuxfoundation Vitess11/5/202317/6/2026
Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that from that point on, anyone who tries to create a new shard from VTAdmin will…
ModificadaBaja (2.7)0.78%—Linuxfoundation Vitess14/4/202317/6/2026
Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing `/` characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list all the keyspaces using `vtctldclient…
ModificadaAlta (8.6)0.76%—Gravitee API Management3/1/202317/6/2026
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
ModificadaMedia (6.1)0.71%—Gravitee API Management23/8/202217/6/2026
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.
ModificadaMedia (4.3)1.3%—Vitejs Vite18/8/202217/6/2026
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
ModificadaCrítica (9.8)1.7%—Vitec Exterity AvediaserverVitec Exterity Avediastream Encoders FirmwareVitec Avediastream M9605 FirmwareVitec Avediastream M9400 Firmware+68/10/202117/6/2026
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
ModificadaMedia (6.1)0.82%—Invitebox10/9/202117/6/2026
The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.1.
ModificadaAlta (7.5)1.3%—Invite Anyone Project Invite Anyone16/8/201917/6/2026
The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.
ModificadaAlta (8.8)0.65%—Invite Anyone Project Invite Anyone16/8/201917/6/2026
The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
ModificadaCrítica (9.8)1.8%—Invite Anyone Project Invite Anyone16/8/201917/6/2026
The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
ModificadaAlta (7.5)1.1%—Vitemoneycoin Project Vitemoneycoin9/7/201817/6/2026
The mintToken function of a smart contract implementation for ViteMoneyCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaCrítica (9.8)2.7%💥 ExploitTechjoomla Invitex17/2/201817/6/2026
SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action.
ModificadaAlta (7.4)1.5%—Savitech-ic Savitech Driver10/11/201717/6/2026
Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Authorities store, aka "Inaudible Subversion."
ModificadaAlta (8.2)2.3%—Envitech Envidas Ultimate17/10/201717/6/2026
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely.
ModificadaMedia (5.3)1.8%—Teleogistic Invite Anyone17/3/201717/6/2026
An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.
ModificadaBaja (3.5)0.95%—Node Invite Project Node Invite21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.
ModificadaMedia (5.8)1.2%—Node Invite Project Node Invite21/4/201517/6/2026
Open redirect vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.
ModificadaMedia (6.8)0.64%—Node Invite Project Node Invite21/4/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to hijack the authentication of users with the "node_invite_can_manage_invite" permission for requests that re-enable node invitations via unspecified vectors.
ModificadaBaja (3.5)0.84%—Drupal Asin Field ModuleDrupalDrupal E-commerce ModuleDrupal Fullname Field FOR CCK+622/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments…