Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.68% | 💥 PoC | Teampass | 31/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Alta (8.8) | 1.6% | 💥 PoC | Teampass | 24/5/2023 | 17/6/2026 | Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Media (5.4) | 0.46% | — | Activecampaign | 15/5/2023 | 17/6/2026 | The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.61% | 💥 PoC | Teampass | 9/5/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7. | |
| Modificada | Media (5.4) | 0.61% | 💥 PoC | Teampass | 5/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7. | |
| Modificada | Crítica (9.1) | 1.5% | — | Apache Streampark | 1/5/2023 | 17/6/2026 | Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow malicious attackers to send any username to… | |
| Modificada | Crítica (9.8) | 1.3% | — | Apache Streampark | 1/5/2023 | 17/6/2026 | Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later | |
| Modificada | Media (5.4) | 1.1% | — | Apache Streampark | 1/5/2023 | 17/6/2026 | Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's possible to modify LDAP statements through techniques similar to… | |
| Modificada | Alta (7.5) | 1.5% | — | Powerampapp Poweramp | 14/4/2023 | 17/6/2026 | An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue and Select Folders button in Library | |
| Modificada | Media (5.4) | 0.36% | — | Teampass | 13/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3. | |
| Modificada | Crítica (9.8) | 1.5% | — | Powerampapp Poweramp | 11/4/2023 | 17/6/2026 | An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters. | |
| Modificada | Alta (7.5) | 8.4% | 💥 Exploit | Teampass | 21/3/2023 | 17/6/2026 | SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | |
| Modificada | Media (5.4) | 0.52% | — | Teampass | 17/3/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | |
| Modificada | Media (5.4) | 0.44% | — | Campaign URL Builder Project Campaign URL Builder | 13/3/2023 | 17/6/2026 | The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.1) | 0.82% | — | Teampass | 27/2/2023 | 17/6/2026 | External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. | |
| Modificada | Alta (8.8) | 0.75% | — | Ampache | 10/2/2023 | 17/6/2026 | SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop. | |
| Modificada | Media (6.1) | 0.64% | — | Ampache | 1/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7. | |
| Modificada | Media (4.3) | 0.48% | — | Activecampaign FOR Woocommerce | 9/1/2023 | 17/6/2026 | The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs. | |
| Modificada | Alta (8.8) | 0.78% | — | Ampache | 23/12/2022 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6. | |
| Modificada | Media (6.5) | 1.4% | — | Adobe Campaign | 16/12/2022 | 6/8/2026 | Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation… | |
| Modificada | Media (6.1) | 1.1% | — | Teampass | 28/3/2022 | 17/6/2026 | Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO. | |
| Modificada | Alta (7.5) | 0.79% | — | Teampasswordmanager Team Password Manager | 19/11/2021 | 17/6/2026 | Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning. | |
| Modificada | Alta (8.8) | 0.43% | — | Teampasswordmanager Team Password Manager | 19/11/2021 | 17/6/2026 | Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import. | |
| Modificada | Alta (7.5) | 3.7% | — | Adobe Campaign | 17/11/2021 | 17/6/2026 | Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server. | |
| Modificada | Media (5.4) | 0.84% | 💥 PoC | Ampache | 22/6/2021 | 17/6/2026 | Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been… |