Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.24% | — | Zoho Campaigns | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.7. | |
| Modificada | Alta (8.8) | 0.24% | — | Zoho Campaigns | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.7. | |
| Modificada | Crítica (9.8) | 0.35% | — | Activecampaign | 15/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14. | |
| Analizada | Alta (8.6) | 0.46% | — | Tamparongj03 Online Graduate Tracer System | 9/4/2024 | 17/6/2026 | Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fetch_gendercs.php. | |
| Modificada | Alta (7.5) | 0.65% | — | Tamparongj03 Online Graduate Tracer System | 9/4/2024 | 17/6/2026 | Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_cs.php. | |
| Aplazada | Alta (8.5) | 0.52% | — | Zoho CampaignsAI | 28/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.6. | |
| Analizada | Media (5.9) | 0.55% | — | Ampache | 27/3/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerability in ampache before v6.3.1 allows a remote attacker to execute code via a crafted payload to serval parameters in the post request of /preferences.php?action=admin_update_preferences. This… | |
| Analizada | Media (6.1) | 0.52% | — | Ampache | 27/3/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabilities,this means that all forms in the Ampache that use `rule` as a variable are not secure. For example, when querying a song, when querying a podcast, we need to use `$rule` variable. This… | |
| Modificada | Crítica (9.6) | 1.7% | — | Mate-desktop Engrampa | 5/2/2024 | 17/6/2026 | Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command Execution (RCE) on the target. While handling CPIO archives, the Engrampa Archive manager follows symlink, cpio by default will follow… | |
| Modificada | Alta (7.2) | 2.3% | — | Apache Streampark | 15/12/2023 | 17/6/2026 | In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark… | |
| Modificada | Media (4.9) | 0.85% | — | Apache Streampark | 15/12/2023 | 17/6/2026 | In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the jobName field may receive illegal parameters, leading to SQL… | |
| Modificada | Media (6.1) | 0.41% | — | Campaignmonitor Campaign Monitor | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Reflected XSS.This issue affects Campaign Monitor for WordPress: from n/a through 2.8.12. | |
| Modificada | Alta (8.1) | 0.58% | — | Fatcatapps Campaign Monitor Optin CAT | 31/10/2023 | 17/6/2026 | The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS. | |
| Modificada | Media (5.9) | 0.41% | — | Palantir Foundry Campaigns | 3/8/2023 | 17/6/2026 | The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint | |
| Modificada | Media (5.4) | 0.63% | — | Teampass | 10/7/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Alta (7.5) | 0.83% | — | Teampass | 8/7/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Media (5.4) | 0.54% | — | Teampass | 8/7/2023 | 17/6/2026 | Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Alta (7.2) | 1.1% | — | Teampass | 8/7/2023 | 17/6/2026 | Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Media (5.4) | 0.54% | — | Teampass | 6/7/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Media (5.4) | 0.54% | — | Teampass | 10/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Media (4.6) | 0.52% | — | Teampass | 10/6/2023 | 17/6/2026 | Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Media (6.5) | 0.38% | — | Teampass | 4/6/2023 | 17/6/2026 | Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Crítica (9) | 0.91% | — | Teampass | 3/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Alta (8.1) | 0.84% | — | Teampass | 3/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Alta (8.7) | 0.74% | — | Teampass | 3/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |