Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

235 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.4%—Ampache30/4/202117/6/2026
Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.
ModificadaAlta (7.5)1.4%—Ampache13/4/202117/6/2026
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For more details and workaround guidance see…
ModificadaMedia (4.3)0.47%—Activecampaign18/3/202117/6/2026
Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account.
AnalizadaAlta (8.6)3.0%—Adobe Campaign13/1/202124/8/2026
Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to…
ModificadaMedia (5.4)0.52%—Hcltech Marketing Campaign17/7/202017/6/2026
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "
ModificadaMedia (5.4)0.54%—Hcltech Marketing Campaign17/7/202017/6/2026
"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."
AnalizadaMedia (5.5)2.3%—Adobe Campaign25/6/202024/8/2026
Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (8.1)1.1%—Teampass4/5/202017/6/2026
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default.
ModificadaAlta (8.8)2.6%—Teampass29/4/202017/6/2026
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.
ModificadaAlta (7.5)8.6%💥 ExploitTeampass29/4/202017/6/2026
TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.
ModificadaAlta (7.5)1.8%—Teampass29/4/202017/6/2026
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.
ModificadaMedia (5.4)0.54%—Teampasswordmanager Team Password Manager16/3/202017/6/2026
Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaMedia (4.3)1.2%—Arialsoftware Campaign Enterprise10/1/202016/6/2026
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.
ModificadaAlta (7.5)1.8%—Arialsoftware Campaign Enterprise10/1/202016/6/2026
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
ModificadaAlta (7.5)1.5%—Arialsoftware Campaign Enterprise10/1/202016/6/2026
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
ModificadaAlta (7.5)1.9%—Arialsoftware Campaign Enterprise10/1/202016/6/2026
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.
ModificadaMedia (6.1)1.0%—Teampass5/10/201917/6/2026
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
ModificadaMedia (5.4)0.63%—Teampass5/10/201917/6/2026
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.
ModificadaMedia (5.4)0.63%—Teampass5/10/201917/6/2026
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.
ModificadaMedia (5.4)0.69%—Teampass26/9/201917/6/2026
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)
ModificadaMedia (5.4)0.84%—Ampache22/8/201917/6/2026
An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.
ModificadaAlta (8.8)1.6%—Ampache22/8/201917/6/2026
An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts,…
ModificadaMedia (5.4)0.76%—Teampass6/8/201917/6/2026
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.
ModificadaAlta (7.5)3.1%—Adobe Campaign18/7/201917/6/2026
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
Orbitaley — Vulnerabilidades