Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.0%—Opmantek Open-audit3/1/20229/7/2026
An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticated attacker to read file outside of the restricted directory.
ModificadaCrítica (9.8)2.0%—Opmantek Open-audit22/12/202117/6/2026
An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.
ModificadaBaja (3.3)1.8%—Adobe Audition20/12/202117/6/2026
Adobe Audition versions 14.4 (and earlier), and 22.0 (and earlier)are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaBaja (3.3)1.8%—Adobe Audition20/12/202117/6/2026
Adobe Audition versions 14.4 (and earlier), and 22.0 (and earlier)are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaBaja (3.3)1.8%—Adobe Audition20/12/202117/6/2026
Adobe Audition versions 14.4 (and earlier), and 22.0 (and earlier)are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (6.1)3.7%💥 ExploitOpmantek Open-audit20/12/202117/6/2026
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.
ModificadaAlta (7.8)0.55%—Wolterskluwer Teammate Audit Management17/12/202117/6/2026
Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files.
ModificadaMedia (6.1)0.81%—Mcafee Policy Auditor23/11/202117/6/2026
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extract…
ModificadaMedia (6.1)0.82%—Mcafee Policy Auditor23/11/202117/6/2026
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the profileNodeID request parameters. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to…
ModificadaMedia (5.5)2.0%—Adobe Audition19/11/202117/6/2026
Adobe Audition version 14.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user…
ModificadaCrítica (9.8)70%💥 ExploitZohocorp Manageengine Adaudit Plus11/11/202117/6/2026
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
AnalizadaMedia (5.5)0.72%—Nsasoft Spotauditor2/11/202129/6/2026
An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering.
ModificadaMedia (5.5)0.66%—Draftpress MY Site Audit16/8/202117/6/2026
The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
ModificadaMedia (6.1)0.76%—Opmantek Open-audit5/2/202117/6/2026
Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already logged in to Open-AudIT before they click the malicious link.
ModificadaMedia (5.9)1.3%💥 PoCOpmantek Open-audit20/1/202117/6/2026
Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the credentials are visible.
ModificadaCrítica (9.8)1.7%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-auditHgiga Msr45 Isherlock-baseHgiga Msr45 Isherlock-user+631/12/202017/6/2026
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
ModificadaAlta (8.8)2.2%—Openfind MailauditOpenfind Mailgates1/11/202017/6/2026
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.
ModificadaMedia (5.3)0.95%—Jenkins Audit Trail8/10/202017/6/2026
In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by adding a suffix to the URL that would be ignored during request handling.
ModificadaMedia (5.3)1.2%—Jenkins Audit Trail8/10/202017/6/2026
Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL.
ModificadaCrítica (9.8)13%—Zohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter PlusZohocorp Manageengine Ad360Zohocorp Manageengine Datasecurity Plus+731/8/202017/6/2026
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus…
ModificadaMedia (4.2)2.5%—OpenldapRedhat Enterprise LinuxOpensuse LeapMcafee Policy Auditor+114/7/202017/6/2026
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
ModificadaAlta (7.8)3.3%—Adobe Audition25/6/202017/6/2026
Adobe Audition versions 13.0.6 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
ModificadaAlta (7.8)3.1%—Adobe Audition25/6/202017/6/2026
Adobe Audition versions 13.0.6 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
ModificadaMedia (5.5)2.9%—Adobe Audition25/6/202017/6/2026
Adobe Audition versions 13.0.5 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaCrítica (9.8)1.9%—Openfind MailauditOpenfind Mailgates23/6/202017/6/2026
Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files.
Orbitaley — Vulnerabilidades