Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)1.0%—Squaredup7/12/202117/6/2026
An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the…
ModificadaMedia (5.4)0.47%—Squaredup7/12/202117/6/2026
A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device.
ModificadaMedia (5.4)0.60%—Squaredup7/12/202117/6/2026
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboard actions.
ModificadaMedia (5.4)0.60%—Squaredup7/12/202117/6/2026
A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file.
ModificadaCrítica (9.8)1.1%—Squaredup6/12/202117/6/2026
An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.
ModificadaMedia (5.3)1.2%—Codesupply Squaretype8/11/202117/6/2026
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.
ModificadaCrítica (9.1)3.9%💥 ExploitThrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+612/4/202117/6/2026
Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes…
ModificadaMedia (5.3)2.1%💥 ExploitThrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+1612/4/202117/6/2026
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive…
ModificadaCrítica (9.1)2.1%—Squarebox Catdv5/3/202117/6/2026
An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such…
ModificadaMedia (5.4)0.87%—Squaredup3/2/202117/6/2026
SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.
ModificadaBaja (3.7)0.93%—Squaredup3/2/202117/6/2026
A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.
ModificadaMedia (6.5)0.78%—Squaredup3/2/202117/6/2026
CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.
ModificadaBaja (3.3)0.34%—Squareup Connect Java Software Development KIT3/2/202117/6/2026
This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary file with the permissions bits of -rw-r--r-- on unix-like systems. On unix-like systems, the system temporary directory is shared between users. As such, the contents of the file downloaded by…
ModificadaMedia (5.9)2.5%—Squareup Okhttp18/4/201917/6/2026
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in…
ModificadaAlta (7.5)4.0%💥 PoCSquareup Retrofit20/12/201817/6/2026
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be…
ModificadaCrítica (9.1)2.2%💥 PoCSquareup Retrofit20/12/201817/6/2026
Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attacker could use this to remotely read files from the file system or to perform SSRF.. This vulnerability appears to have been fixed in After…
ModificadaCrítica (9.8)2.3%—Telesquare Sdt-cs3b1 FirmwareTelesquare Sdt-cw3b1 Firmware21/6/201817/6/2026
Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account.
ModificadaAlta (8.1)0.41%—Square-enix Final Fantasy XIV23/5/201817/6/2026
ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During Transmission in a Communication Channel, allowing a man-in-the-middle attacker to steal user credentials because a session retrieves global.js via http before proceeding to use…
ModificadaAlta (7.5)1.7%💥 PoCSquare-9 Globalforms28/3/201817/6/2026
An issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the "match" parameter allows remote authenticated attackers to execute arbitrary SQL commands. It is possible to upgrade access to full server compromise via xp_cmdshell. In some cases, the authentication requirement for…
ModificadaMedia (5.9)2.2%💥 PoCSquareup OkhttpSquareup Okhttp330/1/201717/6/2026
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
ModificadaCrítica (9.8)4.8%—Squareup Git-fastclone3/11/201617/6/2026
git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to "cd " and "git clone " commands in the library.
ModificadaAlta (8.8)5.2%—Squareup Git-fastclone3/11/201617/6/2026
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, they can get a client to run an arbitrary shell command. Alternately, if an attacker can MITM an unencrypted git clone, they could exploit…
ModificadaMedia (5.4)0.85%—Websquare Job-cube30/1/201617/6/2026
Cross-site scripting (XSS) vulnerability in JOB-CUBE -JOB WEB SYSTEM before 1.2.2 and -JOB WEB SYSTEM High Income 1.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)4.5%💥 ExploitAjsquare Zeuscart11/3/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) schltr parameter in a brands action or (2) brand parameter in a viewbrands action to index.php. NOTE: The search parameter vector is already covered by CVE-2010-5322.
ModificadaMedia (4.3)2.6%💥 ExploitAjsquare Zeuscart11/3/201516/6/2026
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to index.php.
Orbitaley — Vulnerabilidades