Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

165 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.5%💥 ExploitHuge-it Catalog6/10/201617/6/2026
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
ModificadaMedia (5.4)0.87%—IBM Information Server FrameworkIBM Infosphere Information Governance CatalogIBM Infosphere Information Server Business Glossary8/8/201617/6/2026
Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and…
ModificadaMedia (6.1)1.0%—Cisco Prime Service Catalog28/7/201617/6/2026
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuz63795.
ModificadaAlta (8)0.83%—HP Service ManagerHP Service Manager MobilityHP Service Manager ServerHP Service Manager Service Request Catalog+219/6/201617/6/2026
HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request…
ModificadaMedia (6.5)1.5%—Cisco Prime Service Catalog12/12/201517/6/2026
Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.
ModificadaMedia (6.5)1.4%—Cisco Prime Service Catalog30/10/201517/6/2026
SQL injection vulnerability in the web framework in Cisco Prime Service Catalog 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuw50843.
ModificadaMedia (4.3)0.96%—IBM Content Template Catalog3/10/201517/6/2026
Cross-site scripting (XSS) vulnerability in IBM Content Template Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before 4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (5.1)1.1%—THE Extensible Catalog Drupal Toolkit Project THE Extensible Catalog Drupal Toolkit18/8/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "administer ncip providers" permission for requests that alter NCIP providers via a crafted request.
ModificadaMedia (4.3)1.3%—Cisco Prime Service Catalog17/6/201517/6/2026
Cisco Cloud Portal in Cisco Prime Service Catalog 9.4.1_vortex on Cloud Portal appliances allows man-in-the-middle attackers to modify data via unspecified vectors, aka Bug ID CSCuh19683.
ModificadaMedia (6.8)0.64%—Web-dorado Spider Catalog15/6/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Spider Catalog module for Drupal allow remote attackers to hijack the authentication of administrators for requests that delete (1) products, (2) ratings, or (3) categories via unspecified vectors.
ModificadaAlta (7.5)2.4%—Cisco Prime Service Catalog28/1/201517/6/2026
The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External…
ModificadaMedia (5.4)0.27%—Shaklee Product Catalog Project Shaklee Product Catalog19/10/201417/6/2026
The Shaklee Product Catalog (aka com.wProductCatalog) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Lappgroup Lapp Group Catalogue30/9/201417/6/2026
The Lapp Group Catalogue (aka com.prinovis.LappKabel) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaBaja (3.5)0.95%—Tahiticlic Taxonomy Grid Catalog25/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Taxonomy Grid : Catalog module for Drupal 6.x-1.6 and earlier allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.3%—Tibco ActivecatalogTibco Collaborative Information Manager7/1/201116/6/2026
Session fixation vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaAlta (7.5)1.7%—Tibco ActivecatalogTibco Collaborative Information Manager7/1/201116/6/2026
Unspecified vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to modify data or obtain sensitive information via a crafted URL.
ModificadaMedia (4.3)1.3%—Tibco ActivecatalogTibco Collaborative Information Manager7/1/201116/6/2026
Cross-site scripting (XSS) vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.3%—Tibco ActivecatalogTibco Collaborative Information Manager7/1/201116/6/2026
Multiple SQL injection vulnerabilities in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.8)2.2%💥 ExploitOpenmairie Opencatalogue20/5/201016/6/2026
Directory traversal vulnerability in scr/soustab.php in OpenMairie Opencatalogue 1.024, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
ModificadaMedia (6.8)0.93%💥 ExploitBlueconstantmedia COM Djcatalog11/10/200916/6/2026
Multiple SQL injection vulnerabilities in the DJ-Catalog (com_djcatalog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.
ModificadaMedia (4.3)1.5%💥 ExploitOnlinetools Easyimagecatalogue1/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in onlinetools.org EasyImageCatalogue 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search and (2) d index.php parameters to index.php, (3) dir parameter to thumber.php, and the d parameter to (4) describe.php and (5) addcomment.php.…
ModificadaAlta (7.5)1.1%💥 ExploitHumayun Shabbir Bhutta ASP Product Catalog24/7/200916/6/2026
SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.
ModificadaAlta (7.5)1.1%—Zokisoft Zoki Catalog17/6/200916/6/2026
SQL injection vulnerability in system/application/controllers/catalog.php in Zoki Soft Zoki Catalog (aka Smart Catalog) allows remote attackers to execute arbitrary SQL commands via the search_text parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)2.3%💥 ExploitHumayun Shabbir Bhutta ASP Product Catalog17/4/200916/6/2026
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb.
ModificadaMedia (4.3)1.5%💥 ExploitHumayun Shabbir Bhutta ASP Product Catalog17/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
Orbitaley — Vulnerabilidades