Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

182 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)4.7%💥 ExploitOretnom23 Simple Subscription Website3/11/202117/6/2026
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
ModificadaAlta (8.8)1.7%—Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions13/9/202117/6/2026
The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.
ModificadaMedia (5.4)0.79%—Prestashop PS Emailsubscription31/3/202117/6/2026
ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1
ModificadaMedia (6.5)0.41%—Creativeitem Neoflex Video Subscription System4/11/202017/6/2026
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
ModificadaMedia (6.1)1.6%—Woocommerce Subscriptions23/7/202017/6/2026
Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.
ModificadaAlta (7.5)2.2%—NokogiriRedhat Cloudforms Management EngineRedhat OpenshiftRedhat Openstack+419/2/202016/6/2026
Nokogiri before 1.5.4 is vulnerable to XXE attacks
ModificadaMedia (6.1)0.66%—Redhat Subscription Asset Manager2/1/202017/6/2026
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
ModificadaMedia (6.5)0.43%—Redhat Subscription Asset Manager11/12/201917/6/2026
katello-headpin is vulnerable to CSRF in REST API
ModificadaMedia (6.5)2.2%—NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+35/11/201917/6/2026
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
ModificadaMedia (6.5)2.1%—NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+35/11/201917/6/2026
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaAlta (8.8)0.85%—Tipsandtricks-hq Category Specific RSS Feed Subscription12/9/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaCrítica (9.1)1.5%—Suse Subscription Management Tool4/10/201817/6/2026
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
ModificadaAlta (8.1)1.5%—Suse Subscription Management Tool4/10/201817/6/2026
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
ModificadaCrítica (9.8)2.0%—Suse Subscription Management Tool4/10/201817/6/2026
A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
ModificadaAlta (7.8)0.36%—Redhat Subscription-manager27/7/201817/6/2026
It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.
ModificadaCrítica (9.8)86%💥 ExploitRedhat Data GridRedhat Jboss A-mqRedhat Jboss BPM SuiteRedhat Jboss Data Virtualization+119/11/201717/6/2026
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat…
ModificadaMedia (6.1)0.75%—Redhat Subscription Asset Manager16/10/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
ModificadaBaja (3.3)0.43%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/4/201717/6/2026
The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.
ModificadaMedia (6)0.56%—HP Centralview Fraud Risk ManagementHP Centralview Roaming Fraud ControlHP Centralview Credit Risk ControlHP Centralview Subscription Fraud Prevention+222/8/201517/6/2026
HP CentralView Fraud Risk Management 11.1, 11.2, and 11.3; CentralView Revenue Leakage Control 4.1, 4.2, and 4.3; CentralView Dealer Performance Audit 2.0 and 2.1; CentralView Credit Risk Control 2.1, 2.2, and 2.3; CentralView Roaming Fraud Control 2.1, 2.2, and 2.3; and CentralView Subscription Fraud Prevention 2.0…
ModificadaMedia (6)0.56%—HP Centralview Revenue Leakage ControlHP Centralview Fraud Risk ManagementHP Centralview Subscription Fraud PreventionHP Centralview Dealer Performance Audit+222/8/201517/6/2026
HP CentralView Fraud Risk Management 11.1, 11.2, and 11.3; CentralView Revenue Leakage Control 4.1, 4.2, and 4.3; CentralView Dealer Performance Audit 2.0 and 2.1; CentralView Credit Risk Control 2.1, 2.2, and 2.3; CentralView Roaming Fraud Control 2.1, 2.2, and 2.3; and CentralView Subscription Fraud Prevention 2.0…
ModificadaAlta (9)2.1%—HP Centralview Revenue Leakage ControlHP Centralview Credit Risk ControlHP Centralview Subscription Fraud PreventionHP Centralview Dealer Performance Audit+222/8/201517/6/2026
HP CentralView Fraud Risk Management 11.1, 11.2, and 11.3; CentralView Revenue Leakage Control 4.1, 4.2, and 4.3; CentralView Dealer Performance Audit 2.0 and 2.1; CentralView Credit Risk Control 2.1, 2.2, and 2.3; CentralView Roaming Fraud Control 2.1, 2.2, and 2.3; and CentralView Subscription Fraud Prevention 2.0…
ModificadaBaja (3.5)0.95%—Simple Subscription Project Simple Subscription15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Simple Subscription module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer blocks" permission to inject arbitrary web script or HTML via vectors related to block content.
AnalizadaAlta (7.5)54%⚠ Explotación activa💥 PoCRedhat Subscription Asset ManagerRedhat Enterprise Linux ServerRubyonrails Rails7/5/201417/6/2026
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
ModificadaAlta (9.3)1.6%—Redhat Subscription Asset Manager23/12/201317/6/2026
Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.