Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.8% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user. | |
| Modificada | Alta (7.5) | 3.1% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Inadequate access control vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. | |
| Modificada | Alta (7.5) | 3.3% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user. | |
| Modificada | Alta (7.5) | 3.1% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper error handling vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. | |
| Modificada | Alta (7.5) | 3.2% | — | Adobe Campaign | 18/7/2019 | 17/6/2026 | Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Insufficient input validation vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. | |
| Modificada | Media (5.4) | 0.67% | — | IBM Campaign | 17/7/2019 | 17/6/2026 | IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152857. | |
| Modificada | Media (4.3) | 2.3% | — | IBM Campaign | 19/6/2019 | 17/6/2026 | IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172. | |
| Modificada | Alta (8.8) | 1.6% | — | Ampache | 24/5/2019 | 17/6/2026 | Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php. | |
| Modificada | Crítica (9.8) | 1.7% | — | Teampass | 4/2/2019 | 17/6/2026 | TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can… | |
| Modificada | Alta (7.8) | 0.31% | — | IBM Campaign | 5/12/2018 | 17/6/2026 | IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-Force ID: 153382. | |
| Modificada | Baja (3.3) | 0.34% | — | IBM Campaign | 9/11/2018 | 17/6/2026 | IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass security due to lack of input validation. IBM X-Force ID: 120206. | |
| Modificada | Media (5.4) | 0.85% | — | IBM Campaign | 7/9/2018 | 17/6/2026 | IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 121153. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Campaign | 7/9/2018 | 17/6/2026 | IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121152. | |
| Modificada | Media (4.3) | 0.96% | — | IBM Campaign | 27/4/2018 | 17/6/2026 | IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154. | |
| Modificada | Alta (8.1) | 1.1% | — | Teampass | 27/11/2017 | 17/6/2026 | TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled by the attacker, edit any item within a read-only directory, delete an arbitrary item, delete the file attachments of an arbitrary item,… | |
| Modificada | Alta (7.5) | 3.5% | — | Teampass | 27/11/2017 | 17/6/2026 | An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to tamper with parameters of a request to upload.files.php, in order to select the… | |
| Modificada | Media (4.9) | 0.92% | — | Teampass | 27/11/2017 | 17/6/2026 | TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the application, or delete any arbitrary role. To exploit the vulnerability, an authenticated attacker must have the manager rights on… | |
| Modificada | Media (4.9) | 0.92% | — | Teampass | 27/11/2017 | 17/6/2026 | TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administrator. To exploit the vulnerability, an authenticated attacker… | |
| Modificada | Media (5.4) | 0.95% | — | Teampass | 27/11/2017 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or (2) user log history. To exploit the vulnerability, the attacker must be first authenticated to the application. For the… | |
| Modificada | Media (5.4) | 0.95% | — | Teampass | 12/10/2017 | 17/6/2026 | Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | |
| Modificada | Crítica (9.8) | 1.0% | — | Teampass | 5/6/2017 | 17/6/2026 | TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php. | |
| Modificada | Crítica (9.8) | 3.4% | 💥 Exploit | Teampass | 12/4/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action… | |
| Modificada | Alta (8.8) | 3.1% | 💥 Exploit | Teampass | 12/4/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Teampass | 12/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a role. | |
| Modificada | Crítica (9.1) | 3.7% | — | Adobe Campaign | 12/4/2017 | 17/6/2026 | Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campaign database. |