Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.78%—Woorockets Corsa20/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5.
ModificadaMedia (4.8)0.39%—Wpexperts Rocket Maintenance Mode & Coming Soon Page14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpexpertsio Rocket Maintenance Mode & Coming Soon Page allows Stored XSS.This issue affects Rocket Maintenance Mode & Coming Soon Page: from n/a through 4.3.
ModificadaAlta (8.8)0.21%—Qwerty23 Rocket Font21/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions.
ModificadaMedia (4.8)0.30%—Greenrocketsecurity Greenradius14/9/202317/6/2026
A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Configuration" screen of the GreenRADIUS web admin interface. This issue is found in GreenRADIUS v5.1.1.1 and prior. A fix was included in v5.1.2.2.
ModificadaCrítica (9.8)90%💥 ExploitApache Rocketmq12/7/202317/6/2026
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration…
ModificadaMedia (6.1)0.39%—Rocketsoft Rocket LMS30/6/202317/6/2026
A vulnerability was found in RocketSoft Rocket LMS 1.7. It has been declared as problematic. This vulnerability affects unknown code of the file /contact/store of the component Contact Form. The manipulation of the argument name/subject/message leads to cross site scripting. The attack can be initiated remotely. The…
ModificadaMedia (4.8)0.39%—Elightup Erocket22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in eLightUp eRocket plugin <= 1.2.4 versions.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitApache Rocketmq24/5/202317/6/2026
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update…
ModificadaMedia (5.4)0.36%—Berocket Brands FOR Woocommerce18/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions.
ModificadaMedia (5.3)0.61%—Rocket.chat11/5/202317/6/2026
A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated users when there is at least one custom emoji uploaded to the Rocket.Chat instance. The vulnerability causes a delay in the server response, with the potential for limited…
ModificadaMedia (6.1)0.39%—Rocket.chat11/5/202317/6/2026
A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allows the insertion of malicious tags. This can be exploited on servers with content security policy disabled possible leading to some issues attacks like account takeover.
ModificadaMedia (4.3)0.41%—Rocket.chat11/5/202317/6/2026
A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a username is a member of a channel that…
ModificadaAlta (7.5)0.72%—Rocket.chat11/5/202317/6/2026
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the service unresponsive.
ModificadaMedia (6.5)0.39%—Rocket.chat11/5/202317/6/2026
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.
ModificadaMedia (5.3)0.26%—Rocket.chat9/5/202317/6/2026
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.
ModificadaMedia (5.3)0.23%—Rocket.chat9/5/202317/6/2026
A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.
ModificadaCrítica (9.8)0.72%—Rocket.chat9/5/202317/6/2026
A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a compromised account even after 2FA is enabled.
ModificadaMedia (6.1)0.38%—Rocketapps Open Graphite8/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rocket Apps Open Graphite plugin <= 1.6.0 versions.
ModificadaAlta (7.5)0.28%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.
ModificadaAlta (8.8)0.90%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process.
ModificadaCrítica (9.8)0.92%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.
ModificadaAlta (8.8)0.91%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.
ModificadaAlta (8.8)0.84%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.
ModificadaCrítica (9.8)1.4%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.
ModificadaCrítica (9.8)62%💥 ExploitRocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the…
Orbitaley — Vulnerabilidades