Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Npds Revolution | 3/2/2015 | 17/6/2026 | SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL commands via the query parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Modx Revolution | 22/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in manager/assets/fileapi/FileAPI.flash.image.swf in MODX Revolution 2.3.2-pl allows remote attackers to inject arbitrary web script or HTML via the callback parameter. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Modx Revolution | 3/12/2014 | 17/6/2026 | MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Modx Revolution | 3/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject arbitrary web script or HTML via the context_key parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Modx Revolution | 3/12/2014 | 17/6/2026 | MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CSRF token or via a (2) long string in the CSRF token parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Modx Revolution | 6/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in MODX Revolution 2.3.1-pl and earlier allows remote attackers to inject arbitrary web script or HTML via the "a" parameter to manager/. NOTE: this issue exists because of a CVE-2014-2080 regression. | |
| Modificada | Media (5.4) | 0.27% | — | News Revolution - Bahrain Project News Revolution - Bahrain | 21/10/2014 | 17/6/2026 | The news revolution - bahrain (aka com.news.revolution.BH) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Synrevoice Safe Arrival | 19/10/2014 | 17/6/2026 | The Safe Arrival (aka com.synrevoice.safearrival) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.2% | — | Modx Revolution | 24/4/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) session ID (PHPSESSID) to index.php or remote authenticated users to execute arbitrary SQL commands via the (2) user parameter to connectors/security/message.php or (3) id… | |
| Modificada | Alta (7.5) | 1.2% | — | Modx Revolution | 11/3/2014 | 17/6/2026 | SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Modx Revolution | 1/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter. | |
| Modificada | Media (4.3) | 19% | 💥 Exploit | Modx Revolution | 7/10/2012 | 16/6/2026 | Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third… | |
| Modificada | Media (4.9) | 1.6% | — | Trevor Mckay CuminRedhat Enterprise MRG | 28/9/2012 | 16/6/2026 | Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to modify Condor attributes and possibly gain privileges via crafted additional parameters in an HTTP POST request, which triggers a job attribute change request to Condor. | |
| Modificada | Media (4.9) | 1.6% | — | Trevor Mckay CuminRedhat Enterprise MRG | 28/9/2012 | 16/6/2026 | Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote attackers to hijack web sessions via a crafted session cookie. | |
| Modificada | Media (6.8) | 0.92% | — | Trevor Mckay CuminRedhat Enterprise MRG | 28/9/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to hijack the authentication of arbitrary users for requests that execute commands via unspecified vectors. | |
| Modificada | Media (4) | 2.2% | — | Trevor Mckay CuminRedhat Enterprise MRG | 28/9/2012 | 16/6/2026 | Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to cause a denial of service (memory consumption) via a large size in an image request. | |
| Modificada | Alta (7.5) | 2.1% | — | Trevor Mckay CuminRedhat Enterprise MRG | 28/9/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in the get_sample_filters_by_signature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to execute arbitrary SQL commands via the (1) agent or (2) object id. | |
| Modificada | Media (4.3) | 2.1% | — | Trevor Mckay CuminRedhat Enterprise MRG | 28/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages." | |
| Modificada | Media (5.8) | 2.2% | — | Trevor Mckay CuminRedhat Enterprise MRG | 28/9/2012 | 16/6/2026 | Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key. | |
| Modificada | Media (5) | 2.3% | — | Trevor Mckay CuminRedhat Enterprise MRG | 28/9/2012 | 16/6/2026 | Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does not properly restrict access to resources, which allows remote attackers to obtain sensitive information via unspecified vectors related to (1) "web pages," (2) "export functionality," and (3) "image viewing." | |
| Modificada | Media (4.3) | 2.4% | — | Trevor Mckay Cumin | 22/4/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cumin before r5238 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) widgets or (2) pages. | |
| Modificada | Baja (2.6) | 2.0% | 💥 Exploit | Modx Revolution | 7/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter. | |
| Modificada | Media (6.8) | 0.67% | — | Postrev Post Revolution | 6/6/2011 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests to (1) ajax-weblog-guardar.php, (2) verpost.php, (3) comments.php, or (4) perfil.php. | |
| Modificada | Media (4.3) | 1.1% | — | Postrev Post Revolution | 6/6/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in common.php in Post Revolution before 0.8.0c-2 allow remote attackers to inject arbitrary web script or HTML via an attribute of a (1) P, a (2) STRONG, a (3) A, a (4) EM, a (5) I, a (6) IMG, a (7) LI, an (8) OL, a (9) VIDEO, or a (10) BLOCKQUOTE element. | |
| Modificada | Media (5) | 1.5% | — | Postrev Post Revolution | 6/6/2011 | 16/6/2026 | common.php in Post Revolution before 0.8.0c-2 allows remote attackers to cause a denial of service (infinite loop) via malformed HTML markup, as demonstrated by an a< sequence. |