Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

175 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
ModificadaMedia (6.1)1.2%—Igniterealtime Openfire2/9/202017/6/2026
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic"…
ModificadaMedia (6.1)1.0%—Igniterealtime Openfire2/9/202017/6/2026
Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in the Server…
ModificadaMedia (6.1)0.62%—Igniterealtime Openfire2/9/202017/6/2026
In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page
ModificadaCrítica (9.1)5.0%—Apache Ignite3/6/202017/6/2026
Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.
ModificadaAlta (8.8)1.7%—Igniterealtime Spark12/5/202017/6/2026
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent with the HTTP request. This allows an…
ModificadaAlta (8.8)1.9%—Codeigniter23/3/202017/6/2026
CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the issue should not be attributed to CodeIgniter. Furthermore, the blog post reference shows an unknown website built with…
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire19/3/202017/6/2026
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire19/3/202017/6/2026
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire19/3/202017/6/2026
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire18/3/202017/6/2026
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
ModificadaMedia (6.1)1.9%💥 ExploitCodeigniter9/1/202016/6/2026
EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.
ModificadaMedia (6.1)1.3%—Igniterealtime Openfire8/1/202017/6/2026
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
ModificadaMedia (6.1)1.2%—Igniterealtime Openfire8/1/202017/6/2026
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
ModificadaMedia (6.1)1.2%—Igniterealtime Openfire8/1/202017/6/2026
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
ModificadaMedia (6.1)1.4%—Igniterealtime Openfire8/1/202017/6/2026
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.
ModificadaAlta (8.8)0.74%—Getigniteup Igniteup12/11/201917/6/2026
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
ModificadaMedia (6.1)0.97%—Getigniteup Igniteup12/11/201917/6/2026
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.
ModificadaMedia (5.3)1.4%—Getigniteup Igniteup12/11/201917/6/2026
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
ModificadaAlta (7.5)3.2%💥 PoCGetigniteup Igniteup12/11/201917/6/2026
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
ModificadaCrítica (9.8)32%💥 ExploitIgniterealtime Openfire24/10/201917/6/2026
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.
ModificadaMedia (5.3)14%💥 ExploitIgniterealtime Openfire24/10/201917/6/2026
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire23/8/201917/6/2026
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.