Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.68% | — | Apache Commons Fileupload | 15/3/2013 | 16/6/2026 | The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. | |
| Modificada | Media (5) | 1.4% | — | Acquia Commons | 31/10/2012 | 16/6/2026 | The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain sensitive information… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Michau Enterprises LLC Commonsense CMS | 9/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in SenseSites CommonSense CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) special.php, (2) article.php, or (3) cat2.php. | |
| Modificada | Baja (2.1) | 1.1% | — | Creative Commons Module Project Creativecommons | 26/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Creative Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote authenticated users with the administer creative commons permission to inject arbitrary web script or HTML via the (1) creativecommons_user_message or (2)… | |
| Modificada | Media (5) | 13% | — | Apache Commons Compress | 29/6/2012 | 16/6/2026 | Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Michau Enterprises Sensesites Commonsense CMS | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | |
| Modificada | Media (5) | 7.2% | — | Apache TomcatApache Commons Daemon | 15/8/2011 | 16/6/2026 | native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to… | |
| Modificada | Media (4.3) | 1.3% | — | Sensesites Commonsense CMS | 23/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in CommonSense CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Paperthin Commonspot Content Server | 2/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Netcommons | 14/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NetCommons before 1.0.11, and 1.1.x before 1.1.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-4165. | |
| Modificada | Alta (8.5) | 2.8% | — | Fedoraproject Commons | 15/8/2007 | 16/6/2026 | Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password, which allows remote attackers to trigger a certain "unexpected / strange response" from an LDAP… | |
| Modificada | Media (6.8) | 1.3% | — | Netcommons | 16/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NetCommons 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Sensesites Commonsense CMS | 13/7/2006 | 16/6/2026 | SQL injection vulnerability in search.php in SenseSites CommonSense CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the Date parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Paperthin Commonspot Content Server | 29/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter. | |
| Modificada | Media (5) | 1.4% | — | Paperthin Commonspot Content Server | 29/12/2005 | 16/6/2026 | PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting error message. |