Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

900 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.13%—LibosdpAI11/11/202417/6/2026
libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. In affected versions an unexpected `REPLY_CCRYPT` or `REPLY_RMAC_I` may be introduced into an active stream when they should not be. Once RMAC_I message can be sent…
AnalizadaMedia (5.3)0.54%—Amttgroup Hibos10/11/202417/6/2026
A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204. It has been classified as critical. Affected is an unknown function of the file /manager/frontdesk/online_status.php. The manipulation of the argument AccountID leads to sql injection. It is possible to launch the attack remotely.…
AnalizadaMedia (5.3)0.39%—Amttgroup Hibos10/11/202417/6/2026
A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown processing of the file /language.php. The manipulation of the argument LangID/LangName/LangEName leads to cross site scripting. The attack may be initiated remotely. The…
AnalizadaMedia (6.1)0.46%—Redhat Codeready StudioRedhat Jboss Enterprise Application PlatformRedhat Openstack PlatformRedhat Single Sign-on+17/11/202417/6/2026
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS)…
AnalizadaCrítica (9.1)0.46%—Ibos1/11/202417/6/2026
IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.
AplazadaAlta (8.4)0.20%—Bosch Smart HomeAI24/10/20245/7/2026
Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file.
ModificadaMedia (4.8)0.28%—Robosoft Robo Gallery24/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through <= 3.2.21.
ModificadaAlta (7.3)0.68%—Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform22/10/202419/8/2026
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.
ModificadaMedia (5.4)0.29%—Cryoutcreations Verbosa17/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cryout-creations Verbosa verbosa allows Stored XSS.This issue affects Verbosa: from n/a through <= 1.2.3.
AnalizadaMedia (4.8)0.28%—Xibosignage Xibo3/9/202417/6/2026
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute JavaScript via the DataSet functionality. Users can design a DataSet with a HTML column which contains JavaScript,…
AnalizadaMedia (5.4)0.28%—Xibosignage Xibo3/9/202417/6/2026
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary JavaScript via the file preview function. Users can upload HTML/CSS/JS files into the Xibo Library via the…
ModificadaAlta (7.5)2.6%—Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Build OF KeycloakRedhat Data Grid+521/8/202424/9/2026
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder…
AnalizadaCrítica (9.8)0.60%—Amttgroup Hibos12/8/202417/6/2026
AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php.
AnalizadaMedia (6.3)0.30%—Yonle Bostr1/8/202417/6/2026
Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscraper is set to true. This vulnerability is fixed in 3.0.10.
AplazadaMedia (6.5)0.44%—Xibosignage XiboAI30/7/202417/6/2026
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplayReport` API route inside the CMS. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the `sortBy` parameter.…
ModificadaMedia (6.5)0.43%—Xibosignage Xibo30/7/202417/6/2026
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column Formulas. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to…
ModificadaMedia (4.9)0.44%—Xibosignage Xibo30/7/202417/6/2026
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted values in to the API for viewing DataSet…
ModificadaAlta (8.1)0.46%—Xibosignage Xibo30/7/202417/6/2026
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the APIs for…
AnalizadaMedia (5.5)0.40%—Amttgroup Hibos9/7/202417/6/2026
AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calendar_remind.php.
AplazadaCrítica (9.1)0.55%—Cloudfoundry Haproxy-boshreleaseAICloudfoundry Routing-releaseAICloudfoundry Cloud FoundryAI3/7/202417/6/2026
When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications. You are affected if you have route-services enabled in routing-release and have configured the…
AnalizadaMedia (5.4)0.17%—Bosscms10/6/202417/6/2026
BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."
ModificadaAlta (8.8)0.32%—Bosathemes Bosa Elementor Addons AND Templates FOR Woocommerce10/6/202417/6/2026
Missing Authorization vulnerability in Bosa Themes Bosa Elementor Addons and Templates for WooCommerce.This issue affects Bosa Elementor Addons and Templates for WooCommerce: from n/a through 1.0.12.
ModificadaMedia (4.3)0.38%—Buddyboss Platform5/6/202417/6/2026
The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request
AnalizadaMedia (5.3)0.43%—Buddyboss4/6/202417/6/2026
The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID included in the request
AplazadaMedia (5.3)0.47%—Robosoft Robo GalleryAI6/5/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RoboSoft Robo Gallery.This issue affects Robo Gallery: from n/a through 3.2.18.
Orbitaley — Vulnerabilidades