Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
216 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | |
| Modificada | Alta (8.8) | 2.2% | — | Smartstorenet | 29/10/2020 | 17/6/2026 | An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain ModelBase.CustomProperties situations. | |
| Modificada | Crítica (9.8) | 1.2% | — | Smartstore | 8/10/2020 | 17/6/2026 | Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file… | |
| Modificada | Media (6.5) | 0.66% | — | Stiltsoft Table Filter AND Charts FOR Confluence Server | 29/8/2020 | 17/6/2026 | The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter). | |
| Modificada | Alta (8.9) | 0.94% | — | Stiltsoft Table Filter AND Charts FOR Confluence Server | 29/8/2020 | 17/6/2026 | The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the provided Markdown markup to the "Table from CSV" macro. | |
| Modificada | Media (6.7) | 0.42% | — | HPE Intelligent ProvisioningHPE Service Pack FOR ProliantHPE Smartstart Scripting Toolkit | 30/7/2020 | 17/6/2026 | A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the… | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Echarts API | 3/6/2020 | 17/6/2026 | Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Echarts API | 3/6/2020 | 17/6/2026 | Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Cloudfastpath Netcharts Server | 3/1/2020 | 17/6/2026 | Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Crítica (9.8) | 2.3% | — | Carts.guru Carts Guru | 20/5/2019 | 17/6/2026 | The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php. | |
| Modificada | Alta (7.5) | 3.2% | — | Highcharts | 14/3/2019 | 17/6/2026 | In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denial of service attack against the SVGRenderer component, aka ReDoS. | |
| Modificada | Crítica (9.8) | 1.6% | — | Echelon Smartserver 1 FirmwareEchelon Smartserver 2 FirmwareEchelon I.lon 100 FirmwareEchelon I.lon 600 Firmware | 24/7/2018 | 17/6/2026 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory… | |
| Modificada | Crítica (9.8) | 0.83% | — | Echelon Smartserver 1 FirmwareEchelon Smartserver 2 FirmwareEchelon I.lon 100 FirmwareEchelon I.lon 600 Firmware | 24/7/2018 | 17/6/2026 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP. | |
| Modificada | Crítica (9.8) | 1.3% | — | Echelon Smartserver 1 FirmwareEchelon Smartserver 2 FirmwareEchelon I.lon 100 FirmwareEchelon I.lon 600 Firmware | 24/7/2018 | 17/6/2026 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface. | |
| Modificada | Crítica (9.8) | 1.2% | — | Echelon Smartserver 1 FirmwareEchelon Smartserver 2 FirmwareEchelon I.lon 100 Firmware | 24/7/2018 | 17/6/2026 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does… | |
| Modificada | Media (6.1) | 1.5% | 💥 PoC | Smartscriptsolutions Domain Trader | 16/4/2018 | 17/6/2026 | XSS exists in Domain Trader 2.5.3 via the recoverlogin.php email_address parameter. | |
| Modificada | Media (5.9) | 2.0% | — | Fedoraproject Spin-kickstarts | 16/10/2017 | 17/6/2026 | fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates. | |
| Modificada | Media (6.1) | 1.1% | — | EMC Smarts Network Configuration Manager | 11/10/2017 | 17/6/2026 | EMC Network Configuration Manager (NCM) 9.3.x, 9.4.0.x, 9.4.1.x, and 9.4.2.x is affected by a reflected cross-site scripting Vulnerability that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Alta (7) | 0.24% | — | Artsproject ArtsKdelibs | 25/7/2017 | 17/6/2026 | aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory. | |
| Modificada | Crítica (9.8) | 3.6% | — | EMC Smarts Network Configuration Manager | 3/2/2017 | 17/6/2026 | EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains an Improper Authentication vulnerability that could potentially be exploited by malicious users to compromise the… | |
| Modificada | Crítica (9.8) | 5.8% | — | EMC Smarts Network Configuration Manager | 3/2/2017 | 17/6/2026 | EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains a Java RMI Remote Code Execution vulnerability that could potentially be exploited by malicious users to compromise… | |
| Modificada | Media (6.1) | 2.2% | — | Tera-charts Project Tera-charts | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin tera-charts v1.0 | |
| Modificada | Media (6.8) | 2.3% | — | Kankun Smartsocket | 9/6/2015 | 17/6/2026 | The Kankun Smart Socket device and mobile application uses a hardcoded AES 256 bit key, which makes it easier for remote attackers to (1) obtain sensitive information by sniffing the network and (2) obtain access to the device by encrypting messages. |