Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
340 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.80% | — | Joomla! | 4/3/2021 | 17/6/2026 | An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues. | |
| Modificada | Media (6.1) | 0.80% | — | Joomla! | 4/3/2021 | 17/6/2026 | An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues. | |
| Modificada | Crítica (9.1) | 1.4% | — | Joomla! | 4/3/2021 | 17/6/2026 | An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat. | |
| Modificada | Crítica (9.1) | 1.4% | — | Joomla! | 4/3/2021 | 17/6/2026 | An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes. | |
| Modificada | Media (5.3) | 1.1% | — | Joomla! | 4/3/2021 | 17/6/2026 | An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret. | |
| Modificada | Media (6.1) | 0.77% | — | Joomla! | 12/1/2021 | 17/6/2026 | An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors. | |
| Modificada | Media (6.1) | 79% | — | Joomla! | 12/1/2021 | 17/6/2026 | An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks. | |
| Modificada | Media (5.3) | 1.2% | — | Joomla! | 12/1/2021 | 17/6/2026 | An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules. | |
| Modificada | Alta (7.5) | 6.3% | — | Joomla! | 28/12/2020 | 17/6/2026 | An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations. | |
| Modificada | Media (6.3) | 0.40% | — | Joomla! | 28/12/2020 | 17/6/2026 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability. | |
| Modificada | Media (5.3) | 1.1% | — | Joomla! | 28/12/2020 | 17/6/2026 | An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page. | |
| Modificada | Crítica (9.8) | 29% | — | Joomla! | 28/12/2020 | 17/6/2026 | An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list. | |
| Modificada | Alta (7.5) | 1.6% | — | Joomla! | 28/12/2020 | 17/6/2026 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Joomla! | 28/12/2020 | 17/6/2026 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values. | |
| Modificada | Alta (7.5) | 1.4% | — | Joomla! | 28/12/2020 | 17/6/2026 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms. | |
| Modificada | Media (6.1) | 1.0% | — | Joomla! | 26/8/2020 | 17/6/2026 | An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks. | |
| Modificada | Media (6.1) | 1.0% | — | Joomla! | 26/8/2020 | 17/6/2026 | An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect. | |
| Modificada | Media (6.3) | 0.52% | — | Joomla! | 15/7/2020 | 17/6/2026 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. | |
| Modificada | Media (5.3) | 0.58% | — | Joomla! | 15/7/2020 | 17/6/2026 | An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. | |
| Modificada | Media (5.3) | 1.4% | — | Joomla! | 15/7/2020 | 17/6/2026 | An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials | |
| Modificada | Media (4.3) | 0.88% | — | Joomla! | 15/7/2020 | 17/6/2026 | An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users. | |
| Modificada | Media (6.1) | 2.8% | — | Joomla! | 15/7/2020 | 17/6/2026 | An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image. | |
| Modificada | Media (6.3) | 0.52% | — | Joomla! | 15/7/2020 | 17/6/2026 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Joomla! | 2/6/2020 | 17/6/2026 | In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users. | |
| Modificada | Media (6.1) | 0.99% | — | Joomla! | 2/6/2020 | 17/6/2026 | In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS. |