Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

130 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)7.9%💥 ExploitChristianwebministries Proclaim22/2/201817/6/2026
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
ModificadaCrítica (9.8)8.1%💥 ExploitChristianwebministries Proclaim22/2/201817/6/2026
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
ModificadaMedia (4.8)0.84%—Webmin30/12/201717/6/2026
custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.
ModificadaMedia (6.1)4.8%💥 ExploitWebmin19/10/201717/6/2026
Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then send an XSS payload that will lead to…
ModificadaAlta (8.8)3.2%💥 ExploitWebmin19/10/201717/6/2026
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.
ModificadaAlta (8.6)8.9%💥 ExploitWebmin19/10/201717/6/2026
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
ModificadaMedia (6.1)1.4%—Webmin4/7/201717/6/2026
Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these issues were not fixed in 1.840.
ModificadaMedia (6.1)1.7%—Webmin28/4/201717/6/2026
Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)1.1%—Webmin Usermin12/4/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690.
ModificadaMedia (4.9)0.37%—Webmin10/2/201517/6/2026
The Read Mail module in Webmin 1.720 allows local users to read arbitrary files via a symlink attack on an unspecified file.
ModificadaBaja (2.6)0.90%—Webmin20/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.
ModificadaMedia (4.3)0.93%—Webmin20/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.
ModificadaMedia (4.3)1.4%—Webmin Usermin20/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in Usermin before 1.600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.
ModificadaMedia (6.8)1.3%—Webmin Usermin21/6/201417/6/2026
Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.
ModificadaMedia (4.3)1.4%—Webmin UserwinWebmin30/5/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attackers to inject arbitrary web script or HTML via vectors related to popup windows.
ModificadaMedia (4.3)1.6%—Webmin16/3/201417/6/2026
Cross-site scripting (XSS) vulnerability in view.cgi in Webmin before 1.680 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
ModificadaMedia (6.8)0.85%—Gentoo Webmin11/9/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.
ModificadaMedia (5)20%—Gentoo Webmin11/9/201216/6/2026
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.
ModificadaMedia (6.5)62%💥 ExploitGentoo Webmin11/9/201216/6/2026
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
ModificadaMedia (6)2.1%—Gentoo Webmin11/9/201216/6/2026
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.
ModificadaMedia (4.3)3.5%💥 ExploitWebminimalist WEB Minimalist 20090128/9/201116/6/2026
Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
ModificadaMedia (4.3)1.9%—Webmin31/5/201116/6/2026
Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier allows local users to inject arbitrary web script or HTML via a chfn command that changes the real (aka Full Name) field, related to useradmin/index.cgi and useradmin/user-lib.pl.
ModificadaMedia (4.3)1.6%—Webmin UserminWebmin5/1/201016/6/2026
Cross-site scripting (XSS) vulnerability in Webmin before 1.500 and Usermin before 1.430 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.7%—Provider4u Vsftpd Webmin Module30/12/200916/6/2026
Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues."
ModificadaMedia (4.3)1.2%—Webmin UserminWebmin12/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary web script or HTML via the search parameter to webmin_search.cgi (aka the search section), and possibly other components accessed through a "search box" or "open file box." NOTE:…
Orbitaley — Vulnerabilidades