Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.7% | — | Estrutura-basica Project Estrutura-basica | 10/10/2019 | 17/6/2026 | The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter. | |
| Modificada | Media (6.5) | 5.3% | — | Microsoft Exchange ServerMicrosoft LyncMicrosoft Lync BasicMicrosoft Mail AND Calendar+5 | 15/7/2019 | 17/6/2026 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security… | |
| Modificada | Media (5.3) | 1.3% | — | Schneider-electric Somachine BasicSchneider-electric Modicon M221 Firmware | 22/5/2019 | 17/6/2026 | A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause remote launch of SoMachine Basic when sending crafted ethernet message. | |
| Modificada | Media (5.5) | 0.31% | — | Schneider-electric Somachine BasicSchneider-electric Modicon M221 Firmware | 22/5/2019 | 17/6/2026 | An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMachine Basic resource files when logged on the system hosting SoMachine Basic. | |
| Modificada | Alta (7.5) | 1.1% | — | Schneider-electric Somachine BasicSchneider-electric Modicon M221 Firmware | 22/5/2019 | 17/6/2026 | An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while the Ethernet/IP adapter is activated. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.5) | 1.6% | — | Siemens Simatic Cp443-1 OPC UA FirmwareSiemens Simatic ET 200 Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic IPC Diagmonitor FirmwareSiemens Simatic NET PC Software Firmware+23 | 17/4/2019 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) (All versions < V15.1 Upd 4), SIMATIC HMI Comfort Panels 4" - 22" (incl.… | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens Cp1604 FirmwareSiemens Cp1616 FirmwareSiemens Simatic Rf185c FirmwareSiemens Simatic Cp343-1 Advanced Firmware+49 | 17/4/2019 | 17/6/2026 | The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the… | |
| Modificada | Media (6.5) | 1.6% | — | Basic B2B Script Project Basic B2B Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory. | |
| Modificada | Media (5.4) | 0.65% | — | Basic B2B Script Project Basic B2B Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field. | |
| Modificada | Alta (8.8) | 0.65% | — | Basic B2B Script Project Basic B2B Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature. | |
| Modificada | Crítica (9.8) | 1.7% | — | Gigasetpro Maxwell Basic Firmware | 20/12/2018 | 17/6/2026 | Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password). | |
| Modificada | Media (5.9) | 5.5% | — | Microsoft LyncMicrosoft Lync BasicMicrosoft OfficeMicrosoft Office 365 Proplus+2 | 14/11/2018 | 17/6/2026 | A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype. | |
| Modificada | Alta (8.2) | 0.66% | — | Schneider-electric Somachine Basic | 2/11/2018 | 17/6/2026 | A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device. | |
| Modificada | Media (5.4) | 0.66% | — | Readymadeb2bscript Basic B2B | 4/8/2018 | 17/6/2026 | PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields. | |
| Modificada | Alta (7.5) | 1.6% | — | Schneider-electric Somachine Basic | 3/7/2018 | 17/6/2026 | Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. The vulnerability is triggered when input passed to the xml… | |
| Modificada | Alta (8.1) | 1.9% | — | Oracle Financial Services Basel Regulatory Capital Basic | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Financial Services Basel Regulatory Capital Basic | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (7.5) | 2.7% | — | Siemens Telecontrol Server Basic | 25/1/2018 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Server Basic's webserver (port 80/tcp or 443/tcp) could cause a Denial-of-Service condition on the web server. The remaining functionality of the TeleControl Server Basic is not affected by the… | |
| Modificada | Alta (8.8) | 1.8% | — | Siemens Telecontrol Server Basic | 25/1/2018 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleControl Server Basic's port 8000/tcp could escalate his privileges and perform administrative operations. | |
| Modificada | Media (5.3) | 2.2% | — | Siemens Telecontrol Server Basic | 25/1/2018 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's port 8000/tcp could bypass the authentication mechanism and read limited information. | |
| Modificada | Media (6.1) | 0.68% | — | Basic JOB Site Script Project Basic JOB Site Script | 27/12/2017 | 17/6/2026 | Readymade Job Site Script has XSS via the keyword parameter to the /job URI. | |
| Modificada | Crítica (9.8) | 1.2% | — | Basic JOB Site Script Project Basic JOB Site Script | 27/12/2017 | 17/6/2026 | Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI. | |
| Modificada | Alta (8.8) | 0.51% | — | Basic JOB Site Script Project Basic JOB Site Script | 27/12/2017 | 17/6/2026 | Readymade Job Site Script has CSRF via the /job URI. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Basic JOB Site Script Project Basic JOB Site Script | 13/12/2017 | 17/6/2026 | Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job. |