Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

216 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.60%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System1/3/202317/6/2026
A vulnerability has been found in SourceCodester Computer Parts Sales and Inventory System 1.0 and classified as problematic. This vulnerability affects unknown code of the file customer.php. The manipulation of the argument FIRST_NAME/LAST_NAME/PHONE_NUMBER leads to cross site scripting. The attack can be initiated…
ModificadaCrítica (9.8)0.67%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System1/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file processlogin. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (5.4)0.84%—Smoothiecharts Smoothie Charts21/12/202217/6/2026
The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.
ModificadaAlta (7.8)0.97%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code.
ModificadaAlta (7.8)0.97%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
ModificadaAlta (7.8)1.0%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
ModificadaAlta (7.8)0.97%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processing component.
ModificadaAlta (7.8)0.97%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
ModificadaMedia (5.4)0.56%—Amcharts\23/8/202217/6/2026
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 at WordPress.
ModificadaAlta (8.8)0.62%—Button Widget Smartsoft18/7/202217/6/2026
The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the smartsoftbutton_settings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious…
ModificadaMedia (6.5)0.92%—Jenkins Dbcharts15/3/202217/6/2026
Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaCrítica (9.8)1.2%—Auto Spare Parts Management Project Auto Spare Parts Management2/3/202217/6/2026
Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
ModificadaAlta (8.8)0.79%—Jenkins Dbcharts15/2/202217/6/2026
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials.
ModificadaAlta (8.8)0.53%—Jenkins Dbcharts15/2/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.
ModificadaAlta (7.5)1.8%—Startserver Project Startserver24/8/202117/6/2026
All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.
ModificadaMedia (5.4)0.50%—Smartstream Transaction Lifecycle Management Reconciliations-premium10/6/202117/6/2026
SmartStream Transaction Lifecycle Management (TLM) Reconciliation Premium (RP) <3.1.0 allows XSS. This was fixed in TLM RP 3.1.0.
ModificadaMedia (6.1)3.0%💥 ExploitSmartstorenet19/5/202117/6/2026
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.
ModificadaCrítica (9.1)1.8%—Smartstorenet19/5/202117/6/2026
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.
ModificadaCrítica (9.8)33%—Smartstore12/5/202117/6/2026
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does not call HtmlUtils.SanitizeHtml on certain text for a forum post.
ModificadaCrítica (9.8)33%—Smartstore12/5/202117/6/2026
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call HtmlUtils.SanitizeHtml on a private message.
ModificadaMedia (5.4)0.87%—HighchartsNetapp Cloud BackupNetapp Oncommand InsightNetapp Oncommand Workflow Automation+15/5/202117/6/2026
Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The potential impact was that content from untrusted sources could execute code in the end user's browser. The vulnerability is patched in…
ModificadaAlta (8.8)0.82%—Smartstorenet19/2/202117/6/2026
An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).
ModificadaMedia (6.3)1.4%—Fusioncharts Apexcharts9/2/202117/6/2026
The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields.
ModificadaMedia (6.1)2.1%💥 ExploitFlexmonster Pivot Table & Charts17/12/202017/6/2026
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.
ModificadaMedia (6.1)2.2%💥 ExploitFlexmonster Pivot Table & Charts17/12/202017/6/2026
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
Orbitaley — Vulnerabilidades