Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.4% | — | Ampache | 30/4/2021 | 17/6/2026 | Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch. | |
| Modificada | Alta (7.5) | 1.4% | — | Ampache | 13/4/2021 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For more details and workaround guidance see… | |
| Modificada | Media (4.3) | 0.47% | — | Activecampaign | 18/3/2021 | 17/6/2026 | Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account. | |
| Analizada | Alta (8.6) | 3.0% | — | Adobe Campaign | 13/1/2021 | 24/8/2026 | Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to… | |
| Modificada | Media (5.4) | 0.52% | — | Hcltech Marketing Campaign | 17/7/2020 | 17/6/2026 | "HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. " | |
| Modificada | Media (5.4) | 0.54% | — | Hcltech Marketing Campaign | 17/7/2020 | 17/6/2026 | "HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field." | |
| Analizada | Media (5.5) | 2.3% | — | Adobe Campaign | 25/6/2020 | 24/8/2026 | Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (8.1) | 1.1% | — | Teampass | 4/5/2020 | 17/6/2026 | Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default. | |
| Modificada | Alta (8.8) | 2.6% | — | Teampass | 29/4/2020 | 17/6/2026 | TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal. | |
| Modificada | Alta (7.5) | 8.6% | 💥 Exploit | Teampass | 29/4/2020 | 17/6/2026 | TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files. | |
| Modificada | Alta (7.5) | 1.8% | — | Teampass | 29/4/2020 | 17/6/2026 | The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function. | |
| Modificada | Media (5.4) | 0.54% | — | Teampasswordmanager Team Password Manager | 16/3/2020 | 17/6/2026 | Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Arialsoftware Campaign Enterprise | 10/1/2020 | 16/6/2026 | A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field. | |
| Modificada | Alta (7.5) | 1.8% | — | Arialsoftware Campaign Enterprise | 10/1/2020 | 16/6/2026 | In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization. | |
| Modificada | Alta (7.5) | 1.5% | — | Arialsoftware Campaign Enterprise | 10/1/2020 | 16/6/2026 | Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved. | |
| Modificada | Alta (7.5) | 1.9% | — | Arialsoftware Campaign Enterprise | 10/1/2020 | 16/6/2026 | Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials. | |
| Modificada | Media (6.1) | 1.0% | — | Teampass | 5/10/2019 | 17/6/2026 | TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed. | |
| Modificada | Media (5.4) | 0.63% | — | Teampass | 5/10/2019 | 17/6/2026 | TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item. | |
| Modificada | Media (5.4) | 0.63% | — | Teampass | 5/10/2019 | 17/6/2026 | TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder. | |
| Modificada | Media (5.4) | 0.69% | — | Teampass | 26/9/2019 | 17/6/2026 | TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.) | |
| Modificada | Media (5.4) | 0.84% | — | Ampache | 22/8/2019 | 17/6/2026 | An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker. | |
| Modificada | Alta (8.8) | 1.6% | — | Ampache | 22/8/2019 | 17/6/2026 | An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts,… | |
| Modificada | Media (5.4) | 0.76% | — | Teampass | 6/8/2019 | 17/6/2026 | An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload. | |
| Modificada | Alta (7.5) | 3.1% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. |