Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

340 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.99%—Joomla!2/6/202017/6/2026
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
ModificadaAlta (8.8)0.70%—Joomla!2/6/202017/6/2026
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
ModificadaMedia (5.3)0.80%—Joomla!21/4/202017/6/2026
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.
ModificadaMedia (5.3)2.8%💥 PoCJoomla!21/4/202017/6/2026
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
ModificadaMedia (5.3)0.76%—Joomla!21/4/202017/6/2026
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.
ModificadaCrítica (9.8)1.8%—Joomla!16/3/202017/6/2026
An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.
ModificadaMedia (6.1)1.0%—Joomla!16/3/202017/6/2026
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.
ModificadaAlta (8.8)0.72%—Joomla!16/3/202017/6/2026
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
ModificadaMedia (5.3)1.3%—Joomla!16/3/202017/6/2026
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.
ModificadaAlta (8.8)2.7%💥 PoCJoomla!16/3/202017/6/2026
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.
ModificadaAlta (7.5)4.9%💥 PoCJoomla!16/3/202017/6/2026
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.
ModificadaCrítica (9.1)1.9%—Joomla!5/2/202016/6/2026
Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
ModificadaMedia (5.3)0.77%—Joomla!4/2/202016/6/2026
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
ModificadaAlta (7.5)1.6%—Joomla!4/2/202016/6/2026
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
ModificadaAlta (7.5)1.1%—Joomla!4/2/202016/6/2026
Joomla! core 1.7.1 allows information disclosure due to weak encryption
ModificadaMedia (6.1)1.0%—Joomla!28/1/202017/6/2026
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
ModificadaAlta (8.8)0.74%—Joomla!28/1/202017/6/2026
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
ModificadaAlta (8.8)0.45%—Joomla!28/1/202017/6/2026
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
ModificadaMedia (5.4)0.81%—Joomla!22/1/202016/6/2026
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
ModificadaMedia (5.3)0.88%—Joomla!15/1/202016/6/2026
Joomla! 1.5x through 1.5.12: Missing JEXEC Check
ModificadaAlta (7.5)8.9%💥 ExploitJoomla!15/1/202016/6/2026
Joomla! before 2.5.3 allows Admin Account Creation.
ModificadaAlta (7.5)0.89%—Joomla!15/1/202016/6/2026
Joomla! core before 2.5.3 allows unauthorized password change.
ModificadaCrítica (9.8)1.7%—Joomla!18/12/201917/6/2026
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
ModificadaMedia (5.3)1.1%—Joomla!18/12/201917/6/2026
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
ModificadaMedia (5.3)1.1%—Joomla!6/11/201917/6/2026
An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.
Orbitaley — Vulnerabilidades