Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 1.0% | — | Squaredup | 7/12/2021 | 17/6/2026 | An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the… | |
| Modificada | Media (5.4) | 0.47% | — | Squaredup | 7/12/2021 | 17/6/2026 | A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device. | |
| Modificada | Media (5.4) | 0.60% | — | Squaredup | 7/12/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboard actions. | |
| Modificada | Media (5.4) | 0.60% | — | Squaredup | 7/12/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file. | |
| Modificada | Crítica (9.8) | 1.1% | — | Squaredup | 6/12/2021 | 17/6/2026 | An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654. | |
| Modificada | Media (5.3) | 1.2% | — | Codesupply Squaretype | 8/11/2021 | 17/6/2026 | The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request. | |
| Modificada | Crítica (9.1) | 3.9% | 💥 Exploit | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+6 | 12/4/2021 | 17/6/2026 | Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes… | |
| Modificada | Media (5.3) | 2.1% | 💥 Exploit | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+16 | 12/4/2021 | 17/6/2026 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive… | |
| Modificada | Crítica (9.1) | 2.1% | — | Squarebox Catdv | 5/3/2021 | 17/6/2026 | An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such… | |
| Modificada | Media (5.4) | 0.87% | — | Squaredup | 3/2/2021 | 17/6/2026 | SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script. | |
| Modificada | Baja (3.7) | 0.93% | — | Squaredup | 3/2/2021 | 17/6/2026 | A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames. | |
| Modificada | Media (6.5) | 0.78% | — | Squaredup | 3/2/2021 | 17/6/2026 | CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard. | |
| Modificada | Baja (3.3) | 0.34% | — | Squareup Connect Java Software Development KIT | 3/2/2021 | 17/6/2026 | This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary file with the permissions bits of -rw-r--r-- on unix-like systems. On unix-like systems, the system temporary directory is shared between users. As such, the contents of the file downloaded by… | |
| Modificada | Media (5.9) | 2.5% | — | Squareup Okhttp | 18/4/2019 | 17/6/2026 | CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in… | |
| Modificada | Alta (7.5) | 4.0% | 💥 PoC | Squareup Retrofit | 20/12/2018 | 17/6/2026 | Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be… | |
| Modificada | Crítica (9.1) | 2.2% | 💥 PoC | Squareup Retrofit | 20/12/2018 | 17/6/2026 | Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attacker could use this to remotely read files from the file system or to perform SSRF.. This vulnerability appears to have been fixed in After… | |
| Modificada | Crítica (9.8) | 2.3% | — | Telesquare Sdt-cs3b1 FirmwareTelesquare Sdt-cw3b1 Firmware | 21/6/2018 | 17/6/2026 | Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account. | |
| Modificada | Alta (8.1) | 0.41% | — | Square-enix Final Fantasy XIV | 23/5/2018 | 17/6/2026 | ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During Transmission in a Communication Channel, allowing a man-in-the-middle attacker to steal user credentials because a session retrieves global.js via http before proceeding to use… | |
| Modificada | Alta (7.5) | 1.7% | 💥 PoC | Square-9 Globalforms | 28/3/2018 | 17/6/2026 | An issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the "match" parameter allows remote authenticated attackers to execute arbitrary SQL commands. It is possible to upgrade access to full server compromise via xp_cmdshell. In some cases, the authentication requirement for… | |
| Modificada | Media (5.9) | 2.2% | 💥 PoC | Squareup OkhttpSquareup Okhttp3 | 30/1/2017 | 17/6/2026 | OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate. | |
| Modificada | Crítica (9.8) | 4.8% | — | Squareup Git-fastclone | 3/11/2016 | 17/6/2026 | git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to "cd " and "git clone " commands in the library. | |
| Modificada | Alta (8.8) | 5.2% | — | Squareup Git-fastclone | 3/11/2016 | 17/6/2026 | git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, they can get a client to run an arbitrary shell command. Alternately, if an attacker can MITM an unencrypted git clone, they could exploit… | |
| Modificada | Media (5.4) | 0.85% | — | Websquare Job-cube | 30/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in JOB-CUBE -JOB WEB SYSTEM before 1.2.2 and -JOB WEB SYSTEM High Income 1.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Ajsquare Zeuscart | 11/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) schltr parameter in a brands action or (2) brand parameter in a viewbrands action to index.php. NOTE: The search parameter vector is already covered by CVE-2010-5322. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | Ajsquare Zeuscart | 11/3/2015 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to index.php. |