Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.13% | — | LibosdpAI | 11/11/2024 | 17/6/2026 | libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. In affected versions an unexpected `REPLY_CCRYPT` or `REPLY_RMAC_I` may be introduced into an active stream when they should not be. Once RMAC_I message can be sent… | |
| Analizada | Media (5.3) | 0.54% | — | Amttgroup Hibos | 10/11/2024 | 17/6/2026 | A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204. It has been classified as critical. Affected is an unknown function of the file /manager/frontdesk/online_status.php. The manipulation of the argument AccountID leads to sql injection. It is possible to launch the attack remotely.… | |
| Analizada | Media (5.3) | 0.39% | — | Amttgroup Hibos | 10/11/2024 | 17/6/2026 | A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown processing of the file /language.php. The manipulation of the argument LangID/LangName/LangEName leads to cross site scripting. The attack may be initiated remotely. The… | |
| Analizada | Media (6.1) | 0.46% | — | Redhat Codeready StudioRedhat Jboss Enterprise Application PlatformRedhat Openstack PlatformRedhat Single Sign-on+1 | 7/11/2024 | 17/6/2026 | A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS)… | |
| Analizada | Crítica (9.1) | 0.46% | — | Ibos | 1/11/2024 | 17/6/2026 | IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php. | |
| Aplazada | Alta (8.4) | 0.20% | — | Bosch Smart HomeAI | 24/10/2024 | 5/7/2026 | Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file. | |
| Modificada | Media (4.8) | 0.28% | — | Robosoft Robo Gallery | 24/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through <= 3.2.21. | |
| Modificada | Alta (7.3) | 0.68% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform | 22/10/2024 | 19/8/2026 | A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server. | |
| Modificada | Media (5.4) | 0.29% | — | Cryoutcreations Verbosa | 17/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cryout-creations Verbosa verbosa allows Stored XSS.This issue affects Verbosa: from n/a through <= 1.2.3. | |
| Analizada | Media (4.8) | 0.28% | — | Xibosignage Xibo | 3/9/2024 | 17/6/2026 | Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute JavaScript via the DataSet functionality. Users can design a DataSet with a HTML column which contains JavaScript,… | |
| Analizada | Media (5.4) | 0.28% | — | Xibosignage Xibo | 3/9/2024 | 17/6/2026 | Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary JavaScript via the file preview function. Users can upload HTML/CSS/JS files into the Xibo Library via the… | |
| Modificada | Alta (7.5) | 2.6% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Build OF KeycloakRedhat Data Grid+5 | 21/8/2024 | 24/9/2026 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder… | |
| Analizada | Crítica (9.8) | 0.60% | — | Amttgroup Hibos | 12/8/2024 | 17/6/2026 | AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php. | |
| Analizada | Media (6.3) | 0.30% | — | Yonle Bostr | 1/8/2024 | 17/6/2026 | Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscraper is set to true. This vulnerability is fixed in 3.0.10. | |
| Aplazada | Media (6.5) | 0.44% | — | Xibosignage XiboAI | 30/7/2024 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplayReport` API route inside the CMS. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the `sortBy` parameter.… | |
| Modificada | Media (6.5) | 0.43% | — | Xibosignage Xibo | 30/7/2024 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column Formulas. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to… | |
| Modificada | Media (4.9) | 0.44% | — | Xibosignage Xibo | 30/7/2024 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted values in to the API for viewing DataSet… | |
| Modificada | Alta (8.1) | 0.46% | — | Xibosignage Xibo | 30/7/2024 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the APIs for… | |
| Analizada | Media (5.5) | 0.40% | — | Amttgroup Hibos | 9/7/2024 | 17/6/2026 | AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calendar_remind.php. | |
| Aplazada | Crítica (9.1) | 0.55% | — | Cloudfoundry Haproxy-boshreleaseAICloudfoundry Routing-releaseAICloudfoundry Cloud FoundryAI | 3/7/2024 | 17/6/2026 | When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications. You are affected if you have route-services enabled in routing-release and have configured the… | |
| Analizada | Media (5.4) | 0.17% | — | Bosscms | 10/6/2024 | 17/6/2026 | BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code." | |
| Modificada | Alta (8.8) | 0.32% | — | Bosathemes Bosa Elementor Addons AND Templates FOR Woocommerce | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Bosa Themes Bosa Elementor Addons and Templates for WooCommerce.This issue affects Bosa Elementor Addons and Templates for WooCommerce: from n/a through 1.0.12. | |
| Modificada | Media (4.3) | 0.38% | — | Buddyboss Platform | 5/6/2024 | 17/6/2026 | The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request | |
| Analizada | Media (5.3) | 0.43% | — | Buddyboss | 4/6/2024 | 17/6/2026 | The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID included in the request | |
| Aplazada | Media (5.3) | 0.47% | — | Robosoft Robo GalleryAI | 6/5/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RoboSoft Robo Gallery.This issue affects Robo Gallery: from n/a through 3.2.18. |