Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2759▲ 5 respecto a la semana anterior
Críticas / altas1275▼ 253 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
–

2680 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of…
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted…
ModificadaAlta (8.8)2.1%—Coredial Sipxcom4/4/202317/6/2026
CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are able to inject arbitrary arguments into a system command, which can be used to read files from, and write files to, the sipXcom server. This can also be leveraged to gain remote…
ModificadaAlta (8.8)2.5%💥 PoCCoredial Sipxcom4/4/202317/6/2026
CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run commands as the `daemon` user on a sipXcom server can overwrite a service file, and escalate their privileges to `root`.
ModificadaMedia (5.4)0.57%—Pimcore Perspective Editor3/4/202317/6/2026
Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Version…
ModificadaAlta (7.8)0.87%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.87%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.87%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaMedia (5.5)0.83%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaAlta (7.8)0.87%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.93%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaMedia (5.5)0.83%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaMedia (5.5)0.83%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaMedia (5.5)0.81%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaCrítica (9.8)0.98%—Atrocore29/3/202317/6/2026
In Atrocore 1.5.25, the Create Import Feed option with glyphicon-glyphicon-paperclip function is vulnerable to Unauthenticated File upload.
ModificadaMedia (5.4)0.42%—Pimcore29/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.
ModificadaMedia (5.4)0.46%—Pimcore29/3/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
ModificadaMedia (5.4)0.44%—Pimcore29/3/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
ModificadaMedia (5.4)0.44%—Pimcore29/3/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.20.
ModificadaAlta (7)0.36%—Musescore28/3/202317/6/2026
Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code.
ModificadaAlta (8)0.86%—Pimcore22/3/202317/6/2026
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject an arbitrary query by manipulating a user…
ModificadaAlta (8.8)63%—Pimcore22/3/202317/6/2026
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.
ModificadaMedia (5.4)0.54%—Corebos21/3/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0.
ModificadaMedia (4.8)0.40%—Pimcore20/3/202317/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19.
ModificadaMedia (6.1)0.54%—Pimcore20/3/202317/6/2026
Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to…