Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

201 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.4%—Cybozu Garoon9/1/201917/6/2026
Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only for a sign-on user via Single sign-on function.
ModificadaAlta (8.1)1.4%—Cybozu Garoon15/11/201817/6/2026
Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaAlta (8.8)1.2%—Cybozu Garoon26/7/201817/6/2026
SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5.4)0.64%—Cybozu Garoon16/4/201817/6/2026
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)0.97%—Cybozu Garoon16/4/201817/6/2026
Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title of "Cabinet" via unspecified vectors.
ModificadaMedia (5.4)0.64%—Cybozu Garoon16/4/201817/6/2026
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.2%—Cybozu Garoon16/4/201817/6/2026
Cybozu Garoon 4.0.0 to 4.6.0 allows remote authenticated attackers to bypass access restriction to view the closed title of "Space" via unspecified vectors.
ModificadaMedia (4.9)1.3%—Cybozu Garoon16/4/201817/6/2026
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of session authentication via unspecified vectors.
ModificadaBaja (2.7)0.84%—Cybozu Garoon16/4/201817/6/2026
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard database via unspecified vectors.
ModificadaMedia (4.3)0.86%—Cybozu Garoon16/4/201817/6/2026
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a folder and/or notification settings via unspecified vectors.
ModificadaAlta (8.8)1.3%—Cybozu Garoon16/4/201817/6/2026
SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.3%—Cybozu Garoon29/8/201717/6/2026
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".
ModificadaMedia (6.1)0.71%—Cybozu Garoon29/8/201717/6/2026
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function.
ModificadaMedia (5.4)0.54%—Cybozu Garoon29/8/201717/6/2026
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".
ModificadaMedia (5.4)0.54%—Cybozu Garoon29/8/201717/6/2026
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".
ModificadaMedia (4.9)1.1%—Cybozu Garoon29/8/201717/6/2026
Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input
ModificadaMedia (4.8)0.60%—Cybozu Garoon7/7/201717/6/2026
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu.
ModificadaMedia (5.4)0.85%—Cybozu Garoon7/7/201717/6/2026
Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.
ModificadaMedia (5.4)0.85%—Cybozu Garoon7/7/201717/6/2026
Cybozu Garoon 3.0.0 to 4.2.4 may allow an attacker to lock another user's file through a specially crafted page.
ModificadaAlta (8.8)1.6%—Cybozu Garoon9/6/201717/6/2026
SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.
ModificadaMedia (6.5)2.5%—Cybozu Garoon9/6/201717/6/2026
Directory traversal vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)1.1%—Cybozu Garoon9/6/201717/6/2026
Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors.
ModificadaMedia (4.3)1.1%—Cybozu Garoon9/6/201717/6/2026
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.
ModificadaMedia (4.3)1.3%—Cybozu Garoon9/6/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors.
ModificadaMedia (4.3)1.1%—Cybozu Garoon9/6/201717/6/2026
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.
Orbitaley — Vulnerabilidades