Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

175 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.64%—Ignitedcms6/7/201917/6/2026
index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
ModificadaCrítica (9.8)1.6%—Codeigniter-restserver Project Codeigniter-restserver3/7/201917/6/2026
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
ModificadaMedia (6.5)0.44%—Ignitedcms8/8/201817/6/2026
An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.
ModificadaCrítica (9.8)6.7%—Apache Ignite20/7/201817/6/2026
In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one…
ModificadaCrítica (9.8)1.5%—Codeigniter17/6/201817/6/2026
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.
ModificadaMedia (6.1)2.4%—Igniterealtime Openfire13/6/201817/6/2026
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is…
ModificadaAlta (7.4)0.53%—Infragistics Igniteui31/5/201817/6/2026
igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.
ModificadaAlta (8.1)0.92%—Igniterealtime User Import Export15/5/201817/6/2026
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a crafted web request to trigger this vulnerability.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitBroadcom Spring Data CommonsPivotal Software Spring Data RestVmware Spring Data RestApache Ignite+111/4/201826/8/2026
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data…
ModificadaCrítica (9.8)6.3%—Apache Ignite2/4/201817/6/2026
In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially…
ModificadaCrítica (9.8)2.3%—Codeigniter21/2/201817/6/2026
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.
ModificadaMedia (6.1)1.4%—Codeigniter21/2/201816/6/2026
The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
ModificadaAlta (7.5)0.93%—Codeigniter17/11/201717/6/2026
British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.
ModificadaMedia (4.8)0.73%—Igniterealtime Openfire26/10/201717/6/2026
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, injection of…
ModificadaCrítica (9.8)37%💥 ExploitCodeigniter19/9/201717/6/2026
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
ModificadaCrítica (9.8)72%💥 ExploitCodeigniterKohanaframework Kohana19/9/201717/6/2026
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
ModificadaAlta (7.5)1.8%—Igniterealtime Openfire18/8/201717/6/2026
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.
ModificadaAlta (7.5)3.0%—Apache Ignite28/6/201717/6/2026
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system…
ModificadaMedia (5.9)2.0%—Apache Ignite7/4/201717/6/2026
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
ModificadaMedia (5.9)1.5%—Igniterealtime SmackFedoraproject Fedora12/1/201717/6/2026
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
ModificadaCrítica (9.8)3.1%—Codeigniter12/1/201717/6/2026
system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.
ModificadaMedia (6.5)6.0%💥 ExploitIgniterealtime Openfire5/10/201517/6/2026
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.
ModificadaMedia (6.8)65%💥 ExploitIgniterealtime Openfire16/9/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted request to user-password.jsp, (2) add users via a crafted request to user-create.jsp, (3) edit server…
ModificadaMedia (4.3)8.0%💥 ExploitIgniterealtime Openfire16/9/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName parameter to plugins/clientcontrol/create-bookmark.jsp; the (2) urlName parameter to plugins/clientcontrol/create-bookmark.jsp; the (3) hostname…
ModificadaMedia (6.8)0.92%—Redhat Jboss FuseIgniterealtime Smack API25/10/201417/6/2026
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an…
Orbitaley — Vulnerabilidades