Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

216 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.4)2.0%—Xmlhttprequest-ssl Project Xmlhttprequest-ssl23/4/202117/6/2026
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
ModificadaAlta (7.8)2.3%—Microsoft Visual Studio Code Github Pull Requests AND Issues13/4/202117/6/2026
Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability
ModificadaAlta (8.1)4.6%💥 PoCXmlhttprequest Project Xmlhttprequest5/3/202117/6/2026
This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.
ModificadaAlta (7.4)0.91%—Em-http-request Project Em-http-requestFedoraproject Fedora25/5/202017/6/2026
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
ModificadaCrítica (9.8)1.9%—Curlrequest Project Curlrequest7/5/202017/6/2026
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
ModificadaCrítica (9.8)2.9%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+918/2/202016/6/2026
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
ModificadaAlta (7.8)0.26%—Fasttracksoftware Admin BY Request23/1/202017/6/2026
FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privilege at will. If a user does not have direct access to the elevation feature through group policies, they are prompted to enter a PIN code in a challenge-response manner…
ModificadaAlta (7.8)0.31%—Fasttracksoftware Admin BY Request23/1/202017/6/2026
FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privilege at will. When a user requests elevation using the AdminByRequest.exe interface, the interface communicates with the underlying service (Audckq32.exe) using a .NET…
ModificadaCrítica (9.8)3.6%—Requests-kerberos Project Requests-kerberosDebian Linux15/12/201917/6/2026
python-requests-Kerberos through 0.5 does not handle mutual authentication
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaMedia (5.9)0.57%—Http Request Project Http Request23/7/201917/6/2026
OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing.
ModificadaAlta (7.5)2.4%—Bestpractical Request TrackerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux21/3/201917/6/2026
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
ModificadaAlta (8.8)2.9%—BMC Remedy Action Request SystemBMC Remedy Mid-tier21/3/201917/6/2026
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/.
ModificadaMedia (6.5)1.6%—BMC Remedy Action Request System Server3/1/201917/6/2026
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution involving a UserData_Init call.
ModificadaMedia (6.5)0.86%—Otrs Open Ticket Request SystemDebian Linux11/11/201817/6/2026
Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.
ModificadaMedia (4.8)0.55%—Otrs Open Ticket Request System11/11/201817/6/2026
Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL.
ModificadaMedia (4.8)0.67%—Otrs Open Ticket Request SystemDebian Linux11/11/201817/6/2026
Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
ModificadaAlta (7.5)7.4%💥 PoCPython RequestsCanonical Ubuntu LinuxOpensuse LeapRedhat Enterprise Linux Desktop+29/10/201817/6/2026
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
ModificadaMedia (6.5)1.8%—Otrs Open Ticket Request SystemDebian Linux28/9/201817/6/2026
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.
ModificadaMedia (4.3)1.5%—Otrs Open Ticket Request SystemDebian Linux28/9/201817/6/2026
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a logged in user opens it, the email could cause the browser to load external image or CSS resources.
ModificadaAlta (8.8)1.9%—Otrs Open Ticket Request SystemDebian Linux4/8/201817/6/2026
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.
ModificadaAlta (7.5)1.1%—Noderequest Project Noderequest7/6/201817/6/2026
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaMedia (6.5)0.99%—Jenkins Github Pull Request Builder5/6/201817/6/2026
A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing…
ModificadaMedia (5.9)2.6%—Request Project Request4/6/201817/6/2026
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.
ModificadaMedia (6.7)0.36%—Jenkins Github Pull Request Builder5/4/201817/6/2026
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.
Orbitaley — Vulnerabilidades