Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

1962 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.76%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202630/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202630/9/2026
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.1)0.71%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/20265/10/2026
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
AplazadaMedia (5.5)0.53%—Baidu UeditorAIFeehicmsAI7/9/202628/9/2026
A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is…
AplazadaMedia (5.5)0.50%—Light0011 CMSAIUeditorAI4/9/20264/9/2026
A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function catchimage of the file Public/ueditor/php/controller.php of the component UEditor. This manipulation of the argument source[] causes server-side…
AplazadaMedia (5.3)0.21%—WP Edit Password ProtectedAI2/9/20263/9/2026
The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.
Pendiente de análisisMedia (4.8)0.16%—Rockwellautomation Factorytalk Historian Machine EditionAI1/9/20261/9/2026
A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Pendiente de análisisAlta (8.6)0.31%—Rockwellautomation Factorytalk Historian Machine EditionAI1/9/20261/9/2026
A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.
AplazadaMedia (5.3)0.40%—Fastgpt Community EditionAI31/8/20261/9/2026
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all…
AplazadaMedia (5.3)0.58%—Barebones BbeditAI31/8/202631/8/2026
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should…
AplazadaMedia (5.3)0.58%—Barebones BbeditAI31/8/202631/8/2026
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected…
AplazadaMedia (5.1)0.40%—Limesurvey Community EditionAI27/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint. An authenticated user with only the global settings:read permission can directly invoke POST /index.php/admin/menuentries/sa/create and create new survey menu entries without…
AplazadaMedia (4.8)0.41%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.
AplazadaAlta (7.4)0.46%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding. This issue affects…
AplazadaAlta (7.2)0.24%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects LimeSurvey: 7.0.5.
AplazadaAlta (8.4)0.26%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is stored in the surveymenu_entries.data…
AplazadaMedia (6.5)0.22%—Thingsboard Professional EditionAI26/8/20269/9/2026
A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation…
AplazadaAlta (8.5)0.58%—SuneditorAI26/8/20269/9/2026
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled raw embed HTML with DOMParser and processes the resulting DOM nodes. When an external script element follows a valid…
Pendiente de análisisAlta (8.1)0.20%—Drupal Edit In-place FieldAI25/8/202628/8/2026
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.
AplazadaAlta (7.1)0.40%—Dradis Community EditionAI25/8/202624/9/2026
In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a result, any authenticated (non-admin) user can create an AI provider pointing to an…
Pendiente de análisisAlta (7.7)0.20%—Tuleap Enterprise EditionAI25/8/202628/8/2026
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.
AplazadaAlta (8.4)1.1%—Sakura Editor Development Community Sakura EditorAI24/8/202628/8/2026
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
AplazadaAlta (8.6)1.5%—Otrs Community EditionAI20/8/202624/9/2026
OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are…
AplazadaAlta (7.2)0.47%—Humhub Community EditionAI19/8/202628/8/2026
HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into…
AplazadaAlta (7.4)0.46%—Humhub Community EditionAI19/8/202628/8/2026
HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.