Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)58%—Adobe CommerceAdobe Magento Open Source27/3/202317/6/2026
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they…
ModificadaAlta (7.5)0.93%—Adobe CommerceAdobe Magento Open Source27/3/202317/6/2026
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not…
ModificadaAlta (7.2)0.78%—Open Source Sacco Management System Project Open Source Sacco Management System18/10/202217/6/2026
Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php.
ModificadaAlta (7.2)0.88%—Open Source Sacco Management System Project Open Source Sacco Management System17/10/202217/6/2026
Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php.
ModificadaMedia (5.4)11%—Adobe CommerceAdobe Magento Open Source14/10/202217/6/2026
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
ModificadaMedia (5.3)1.3%—Adobe CommerceAdobe Magento Open Source14/10/202217/6/2026
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require…
ModificadaAlta (7.2)0.78%—Open Source Sacco Management System Project Open Source Sacco Management System14/10/202217/6/2026
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_user.php.
ModificadaAlta (7.2)0.78%—Open Source Sacco Management System Project Open Source Sacco Management System14/10/202217/6/2026
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_borrower.php.
ModificadaAlta (7.2)0.90%—Open Source Sacco Management System Project Open Source Sacco Management System12/10/202217/6/2026
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_plan.
ModificadaAlta (7.2)0.90%—Open Source Sacco Management System Project Open Source Sacco Management System12/10/202217/6/2026
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_borrower.
ModificadaAlta (7.2)0.87%—Open Source Sacco Management System Project Open Source Sacco Management System7/10/202217/6/2026
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_payment.
ModificadaAlta (7.2)0.87%—Open Source Sacco Management System Project Open Source Sacco Management System7/10/202217/6/2026
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_loan.
ModificadaAlta (7.2)1.2%—Opensourcepos Open Source Point OF Sale28/7/202217/6/2026
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
ModificadaAlta (7.5)1.4%—Openteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.
ModificadaMedia (5.4)1.1%—Openteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.
ModificadaAlta (7.2)2.1%—Openteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior…
ModificadaMedia (4.8)0.89%—Openteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module.
ModificadaMedia (5.4)1.1%—Openteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.
ModificadaMedia (5.4)1.1%—Openteknik Open Source Social Network25/7/202217/6/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module.
ModificadaAlta (7.2)1.2%—Useful Simple Open-source CMS Project Useful Simple Open-source CMS10/1/202217/6/2026
Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should replace the file `admin/pages/useredit.php` with a newer version. USOC version Pb2.4Bfx3 contains a…
ModificadaAlta (7.2)1.0%—Useful Simple Open-source CMS Project Useful Simple Open-source CMS4/1/202217/6/2026
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site admins. Users are advised to upgrade as…
ModificadaCrítica (9.8)1.2%—Useful Simple Open-source CMS Project Useful Simple Open-source CMS4/1/202217/6/2026
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users are advised to upgrade as soon as…
ModificadaMedia (6.5)1.6%—Adobe CommerceAdobe Magento Open Source15/10/202117/6/2026
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin…
ModificadaAlta (7.5)2.0%—Adobe CommerceAdobe Magento Open Source1/9/202117/6/2026
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-service using a GraphQL field.
ModificadaMedia (6.6)1.9%—Adobe CommerceAdobe Magento Open Source1/9/202117/6/2026
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled.