Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
175 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php. | |
| Modificada | Media (6.1) | 1.2% | — | Igniterealtime Openfire | 2/9/2020 | 17/6/2026 | A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic"… | |
| Modificada | Media (6.1) | 1.0% | — | Igniterealtime Openfire | 2/9/2020 | 17/6/2026 | Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in the Server… | |
| Modificada | Media (6.1) | 0.62% | — | Igniterealtime Openfire | 2/9/2020 | 17/6/2026 | In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page | |
| Modificada | Crítica (9.1) | 5.0% | — | Apache Ignite | 3/6/2020 | 17/6/2026 | Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem. | |
| Modificada | Alta (8.8) | 1.7% | — | Igniterealtime Spark | 12/5/2020 | 17/6/2026 | An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent with the HTTP request. This allows an… | |
| Modificada | Alta (8.8) | 1.9% | — | Codeigniter | 23/3/2020 | 17/6/2026 | CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the issue should not be attributed to CodeIgniter. Furthermore, the blog post reference shows an unknown website built with… | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 19/3/2020 | 17/6/2026 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 19/3/2020 | 17/6/2026 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 19/3/2020 | 17/6/2026 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 18/3/2020 | 17/6/2026 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter. | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Codeigniter | 9/1/2020 | 16/6/2026 | EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks. | |
| Modificada | Media (6.1) | 1.3% | — | Igniterealtime Openfire | 8/1/2020 | 17/6/2026 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents. | |
| Modificada | Media (6.1) | 1.2% | — | Igniterealtime Openfire | 8/1/2020 | 17/6/2026 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page. | |
| Modificada | Media (6.1) | 1.2% | — | Igniterealtime Openfire | 8/1/2020 | 17/6/2026 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp. | |
| Modificada | Media (6.1) | 1.4% | — | Igniterealtime Openfire | 8/1/2020 | 17/6/2026 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents. | |
| Modificada | Alta (8.8) | 0.74% | — | Getigniteup Igniteup | 12/11/2019 | 17/6/2026 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF. | |
| Modificada | Media (6.1) | 0.97% | — | Getigniteup Igniteup | 12/11/2019 | 17/6/2026 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS. | |
| Modificada | Media (5.3) | 1.4% | — | Getigniteup Igniteup | 12/11/2019 | 17/6/2026 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure. | |
| Modificada | Alta (7.5) | 3.2% | 💥 PoC | Getigniteup Igniteup | 12/11/2019 | 17/6/2026 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion. | |
| Modificada | Crítica (9.8) | 32% | 💥 Exploit | Igniterealtime Openfire | 24/10/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests. | |
| Modificada | Media (5.3) | 14% | 💥 Exploit | Igniterealtime Openfire | 24/10/2019 | 17/6/2026 | PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability. | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 23/8/2019 | 17/6/2026 | Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. |