Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.58%—Rocket.chat23/9/202217/6/2026
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code).
ModificadaMedia (6.1)0.55%—Berocket Stockists Manager FOR Woocommerce6/9/202217/6/2026
The Stockists Manager for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2.1. This is due to missing nonce validation on the stockist_settings_main() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and…
ModificadaCrítica (9.1)0.61%—Linuxfoundation Rocket Chip Generator18/7/202217/6/2026
Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala.
ModificadaMedia (4.3)0.74%—Jenkins Rocketchat Notifier30/6/202217/6/2026
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (6.1)1.2%💥 PoCRocketsoftware Ags-zena17/6/20229/7/2026
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
ModificadaAlta (7.5)0.58%—Rocketsoftware Ags-zena17/6/20229/7/2026
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.
ModificadaCrítica (9.8)1.1%—Rocketsoftware Ags-zena17/6/20229/7/2026
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
ModificadaMedia (5.4)0.59%—Servicerocket Linking7/6/202217/6/2026
A vulnerability classified as problematic has been found in Linking. This affects an unknown part of the component New Windows Macro. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
ModificadaMedia (6.1)0.77%—Rocket.chat Livechat1/4/202217/6/2026
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.
ModificadaMedia (4.3)0.74%—Jenkins Rocketchat Notifier29/3/202217/6/2026
A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaMedia (4.3)0.61%—Jenkins Rocketchat Notifier29/3/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential.
ModificadaMedia (6.1)0.88%—Berocket Advanced Product Labels FOR Woocommerce14/3/202217/6/2026
The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.63%—Rocket.chat18/10/202117/6/2026
A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.
ModificadaMedia (6.5)1.6%—Rocket.chat30/8/202117/6/2026
Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13.
ModificadaCrítica (9.8)2.3%—Rocket.chat9/8/202117/6/2026
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
ModificadaAlta (7.5)0.83%—Rocket.chat5/7/202117/6/2026
The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
ModificadaCrítica (9.8)95%💥 ExploitRocket.chat27/5/202117/6/2026
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
ModificadaAlta (7.5)1.9%—Rocket.chat27/5/202117/6/2026
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.
ModificadaAlta (7.8)2.1%—Psyonix Rocket League18/5/202117/6/2026
Epic Games / Psyonix Rocket League <=1.95 is affected by Buffer Overflow. Stack-based buffer overflow occurs when Rocket League handles UPK object files that can result in code execution and denial of service scenario.
ModificadaAlta (7.3)1.0%—Rocket1/4/202117/6/2026
An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-provided function panics.
ModificadaMedia (6.1)1.7%—Rocket.chat26/3/202117/6/2026
Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app.
ModificadaMedia (5.4)0.90%—Rocket.chat26/1/202117/6/2026
Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.
ModificadaMedia (5.4)0.85%—Rocket.chat26/1/202117/6/2026
The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter.
ModificadaMedia (5.4)0.78%—Rocketgenius Gravityforms20/1/202117/6/2026
A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
ModificadaMedia (5.4)0.78%—Rocketgenius Gravityforms20/1/202117/6/2026
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
Orbitaley — Vulnerabilidades