Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
–

2678 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.48%—Pimcore28/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (4.9)1.0%—Pimcore27/4/202317/6/2026
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the `/admin/misc/script-proxy` API endpoint that is accessible by an authenticated administrator user is vulnerable to arbitrary JavaScript and CSS file read via the `scriptPath` and `scripts` parameters. The `scriptPath`…
ModificadaAlta (8.8)0.79%—Pimcore27/4/202317/6/2026
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerability exists in the admin translations API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.
ModificadaAlta (8.8)0.79%—Pimcore27/4/202317/6/2026
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerability exists in the translation export API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.
ModificadaAlta (8.8)0.72%—Pimcore27/4/202317/6/2026
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to receive a patch or, as a workaround, apply the patch manually.
ModificadaMedia (5.4)0.38%—Pimcore27/4/202317/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (5.4)0.42%—Pimcore27/4/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (6.1)1.1%—Pimcore27/4/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (5.4)0.48%—Pimcore27/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (5.4)0.52%—Pimcore27/4/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaAlta (8.8)0.91%—Pimcore27/4/202317/6/2026
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (6.5)0.67%—Pimcore27/4/202317/6/2026
Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (5.4)0.40%—Pimcore27/4/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (5.4)0.40%—Pimcore27/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (5.4)0.51%—Pimcore27/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (5.4)0.56%—Pimcore27/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
ModificadaMedia (5.9)1.0%💥 PoCTrustwallet Trust Wallet Browser ExtensionTrustwallet Trust Wallet Core27/4/202317/6/2026
Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in December 2022 and March 2023. This occurs because the mt19937 Mersenne Twister takes a single 32-bit value as an input seed, resulting in only…
ModificadaMedia (5.3)1.3%💥 PoCOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core PolicyOracle Mysql ConnectorsNetapp Active IQ Unified Manager+218/4/202317/6/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require…
ModificadaCrítica (9.8)2.3%💥 PoCMediawiki Score15/4/202317/6/2026
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted…
ModificadaAlta (7.5)1.1%—Atrocore Atropim14/4/202317/6/2026
Atropim 1.5.26 is vulnerable to Directory Traversal.
ModificadaMedia (5.4)0.32%—SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core11/4/202317/6/2026
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images…
ModificadaMedia (4.6)0.32%—SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core11/4/202317/6/2026
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the…
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when using nicknames. An attacker could create a user account and enter malicious scripts into their profile's…
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of…
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted…