Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.0% | — | Opmantek Open-audit | 3/1/2022 | 9/7/2026 | An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticated attacker to read file outside of the restricted directory. | |
| Modificada | Crítica (9.8) | 2.0% | — | Opmantek Open-audit | 22/12/2021 | 17/6/2026 | An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes. | |
| Modificada | Baja (3.3) | 1.8% | — | Adobe Audition | 20/12/2021 | 17/6/2026 | Adobe Audition versions 14.4 (and earlier), and 22.0 (and earlier)are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Baja (3.3) | 1.8% | — | Adobe Audition | 20/12/2021 | 17/6/2026 | Adobe Audition versions 14.4 (and earlier), and 22.0 (and earlier)are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Baja (3.3) | 1.8% | — | Adobe Audition | 20/12/2021 | 17/6/2026 | Adobe Audition versions 14.4 (and earlier), and 22.0 (and earlier)are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Opmantek Open-audit | 20/12/2021 | 17/6/2026 | Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser. | |
| Modificada | Alta (7.8) | 0.55% | — | Wolterskluwer Teammate Audit Management | 17/12/2021 | 17/6/2026 | Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files. | |
| Modificada | Media (6.1) | 0.81% | — | Mcafee Policy Auditor | 23/11/2021 | 17/6/2026 | A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extract… | |
| Modificada | Media (6.1) | 0.82% | — | Mcafee Policy Auditor | 23/11/2021 | 17/6/2026 | A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the profileNodeID request parameters. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to… | |
| Modificada | Media (5.5) | 2.0% | — | Adobe Audition | 19/11/2021 | 17/6/2026 | Adobe Audition version 14.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user… | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | Zohocorp Manageengine Adaudit Plus | 11/11/2021 | 17/6/2026 | Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. | |
| Analizada | Media (5.5) | 0.72% | — | Nsasoft Spotauditor | 2/11/2021 | 29/6/2026 | An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering. | |
| Modificada | Media (5.5) | 0.66% | — | Draftpress MY Site Audit | 16/8/2021 | 17/6/2026 | The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.76% | — | Opmantek Open-audit | 5/2/2021 | 17/6/2026 | Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already logged in to Open-AudIT before they click the malicious link. | |
| Modificada | Media (5.9) | 1.3% | 💥 PoC | Opmantek Open-audit | 20/1/2021 | 17/6/2026 | Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the credentials are visible. | |
| Modificada | Crítica (9.8) | 1.7% | — | Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-auditHgiga Msr45 Isherlock-baseHgiga Msr45 Isherlock-user+6 | 31/12/2020 | 17/6/2026 | HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism. | |
| Modificada | Alta (8.8) | 2.2% | — | Openfind MailauditOpenfind Mailgates | 1/11/2020 | 17/6/2026 | MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token. | |
| Modificada | Media (5.3) | 0.95% | — | Jenkins Audit Trail | 8/10/2020 | 17/6/2026 | In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by adding a suffix to the URL that would be ignored during request handling. | |
| Modificada | Media (5.3) | 1.2% | — | Jenkins Audit Trail | 8/10/2020 | 17/6/2026 | Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL. | |
| Modificada | Crítica (9.8) | 13% | — | Zohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter PlusZohocorp Manageengine Ad360Zohocorp Manageengine Datasecurity Plus+7 | 31/8/2020 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus… | |
| Modificada | Media (4.2) | 2.5% | — | OpenldapRedhat Enterprise LinuxOpensuse LeapMcafee Policy Auditor+1 | 14/7/2020 | 17/6/2026 | libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux. | |
| Modificada | Alta (7.8) | 3.3% | — | Adobe Audition | 25/6/2020 | 17/6/2026 | Adobe Audition versions 13.0.6 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 3.1% | — | Adobe Audition | 25/6/2020 | 17/6/2026 | Adobe Audition versions 13.0.6 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Media (5.5) | 2.9% | — | Adobe Audition | 25/6/2020 | 17/6/2026 | Adobe Audition versions 13.0.5 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Crítica (9.8) | 1.9% | — | Openfind MailauditOpenfind Mailgates | 23/6/2020 | 17/6/2026 | Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files. |