Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
130 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 7.9% | 💥 Exploit | Christianwebministries Proclaim | 22/2/2018 | 17/6/2026 | Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/. | |
| Modificada | Crítica (9.8) | 8.1% | 💥 Exploit | Christianwebministries Proclaim | 22/2/2018 | 17/6/2026 | Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. | |
| Modificada | Media (4.8) | 0.84% | — | Webmin | 30/12/2017 | 17/6/2026 | custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality. | |
| Modificada | Media (6.1) | 4.8% | 💥 Exploit | Webmin | 19/10/2017 | 17/6/2026 | Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then send an XSS payload that will lead to… | |
| Modificada | Alta (8.8) | 3.2% | 💥 Exploit | Webmin | 19/10/2017 | 17/6/2026 | CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands. | |
| Modificada | Alta (8.6) | 8.9% | 💥 Exploit | Webmin | 19/10/2017 | 17/6/2026 | SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000. | |
| Modificada | Media (6.1) | 1.4% | — | Webmin | 4/7/2017 | 17/6/2026 | Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these issues were not fixed in 1.840. | |
| Modificada | Media (6.1) | 1.7% | — | Webmin | 28/4/2017 | 17/6/2026 | Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 1.1% | — | Webmin Usermin | 12/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690. | |
| Modificada | Media (4.9) | 0.37% | — | Webmin | 10/2/2015 | 17/6/2026 | The Read Mail module in Webmin 1.720 allows local users to read arbitrary files via a symlink attack on an unspecified file. | |
| Modificada | Baja (2.6) | 0.90% | — | Webmin | 20/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924. | |
| Modificada | Media (4.3) | 0.93% | — | Webmin | 20/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924. | |
| Modificada | Media (4.3) | 1.4% | — | Webmin Usermin | 20/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Usermin before 1.600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924. | |
| Modificada | Media (6.8) | 1.3% | — | Webmin Usermin | 21/6/2014 | 17/6/2026 | Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action. | |
| Modificada | Media (4.3) | 1.4% | — | Webmin UserwinWebmin | 30/5/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attackers to inject arbitrary web script or HTML via vectors related to popup windows. | |
| Modificada | Media (4.3) | 1.6% | — | Webmin | 16/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in view.cgi in Webmin before 1.680 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| Modificada | Media (6.8) | 0.85% | — | Gentoo Webmin | 11/9/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982. | |
| Modificada | Media (5) | 20% | — | Gentoo Webmin | 11/9/2012 | 16/6/2026 | file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field. | |
| Modificada | Media (6.5) | 62% | 💥 Exploit | Gentoo Webmin | 11/9/2012 | 16/6/2026 | file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character. | |
| Modificada | Media (6) | 2.1% | — | Gentoo Webmin | 11/9/2012 | 16/6/2026 | Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Webminimalist WEB Minimalist 200901 | 28/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | |
| Modificada | Media (4.3) | 1.9% | — | Webmin | 31/5/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier allows local users to inject arbitrary web script or HTML via a chfn command that changes the real (aka Full Name) field, related to useradmin/index.cgi and useradmin/user-lib.pl. | |
| Modificada | Media (4.3) | 1.6% | — | Webmin UserminWebmin | 5/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Webmin before 1.500 and Usermin before 1.430 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Provider4u Vsftpd Webmin Module | 30/12/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues." | |
| Modificada | Media (4.3) | 1.2% | — | Webmin UserminWebmin | 12/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary web script or HTML via the search parameter to webmin_search.cgi (aka the search section), and possibly other components accessed through a "search box" or "open file box." NOTE:… |