Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.58% | — | Rocket.chat | 23/9/2022 | 17/6/2026 | An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code). | |
| Modificada | Media (6.1) | 0.55% | — | Berocket Stockists Manager FOR Woocommerce | 6/9/2022 | 17/6/2026 | The Stockists Manager for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2.1. This is due to missing nonce validation on the stockist_settings_main() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and… | |
| Modificada | Crítica (9.1) | 0.61% | — | Linuxfoundation Rocket Chip Generator | 18/7/2022 | 17/6/2026 | Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala. | |
| Modificada | Media (4.3) | 0.74% | — | Jenkins Rocketchat Notifier | 30/6/2022 | 17/6/2026 | Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Rocketsoftware Ags-zena | 17/6/2022 | 9/7/2026 | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Alta (7.5) | 0.58% | — | Rocketsoftware Ags-zena | 17/6/2022 | 9/7/2026 | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie. | |
| Modificada | Crítica (9.8) | 1.1% | — | Rocketsoftware Ags-zena | 17/6/2022 | 9/7/2026 | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE). | |
| Modificada | Media (5.4) | 0.59% | — | Servicerocket Linking | 7/6/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Linking. This affects an unknown part of the component New Windows Macro. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (6.1) | 0.77% | — | Rocket.chat Livechat | 1/4/2022 | 17/6/2026 | A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance. | |
| Modificada | Media (4.3) | 0.74% | — | Jenkins Rocketchat Notifier | 29/3/2022 | 17/6/2026 | A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.61% | — | Jenkins Rocketchat Notifier | 29/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential. | |
| Modificada | Media (6.1) | 0.88% | — | Berocket Advanced Product Labels FOR Woocommerce | 14/3/2022 | 17/6/2026 | The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.63% | — | Rocket.chat | 18/10/2021 | 17/6/2026 | A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks. | |
| Modificada | Media (6.5) | 1.6% | — | Rocket.chat | 30/8/2021 | 17/6/2026 | Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13. | |
| Modificada | Crítica (9.8) | 2.3% | — | Rocket.chat | 9/8/2021 | 17/6/2026 | A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE. | |
| Modificada | Alta (7.5) | 0.83% | — | Rocket.chat | 5/7/2021 | 17/6/2026 | The Rocket.Chat desktop application 2.17.11 opens external links without user interaction. | |
| Modificada | Crítica (9.8) | 95% | 💥 Exploit | Rocket.chat | 27/5/2021 | 17/6/2026 | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE. | |
| Modificada | Alta (7.5) | 1.9% | — | Rocket.chat | 27/5/2021 | 17/6/2026 | An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks. | |
| Modificada | Alta (7.8) | 2.1% | — | Psyonix Rocket League | 18/5/2021 | 17/6/2026 | Epic Games / Psyonix Rocket League <=1.95 is affected by Buffer Overflow. Stack-based buffer overflow occurs when Rocket League handles UPK object files that can result in code execution and denial of service scenario. | |
| Modificada | Alta (7.3) | 1.0% | — | Rocket | 1/4/2021 | 17/6/2026 | An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-provided function panics. | |
| Modificada | Media (6.1) | 1.7% | — | Rocket.chat | 26/3/2021 | 17/6/2026 | Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app. | |
| Modificada | Media (5.4) | 0.90% | — | Rocket.chat | 26/1/2021 | 17/6/2026 | Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes. | |
| Modificada | Media (5.4) | 0.85% | — | Rocket.chat | 26/1/2021 | 17/6/2026 | The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter. | |
| Modificada | Media (5.4) | 0.78% | — | Rocketgenius Gravityforms | 20/1/2021 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.). | |
| Modificada | Media (5.4) | 0.78% | — | Rocketgenius Gravityforms | 20/1/2021 | 17/6/2026 | Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.). |