Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

238 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.9)0.37%—Fusionforge14/3/201316/6/2026
(1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5) deb-specific/ssh_dump_update.pl, (6) deb-specific/user_dump_update.pl, (7) plugins/scmbzr/common/BzrPlugin.class.php, (8) plugins/scmcvs/common/CVSPlugin.class.php, (9)…
ModificadaAlta (10)1.7%—Ninjaforge COM Ninjaxplorer24/1/201316/6/2026
Unspecified vulnerability in the NinjaXplorer component before 1.0.7 for Joomla! has unknown impact and attack vectors.
ModificadaMedia (6.9)0.40%—Sony Sound Forge7/9/201216/6/2026
Untrusted search path vulnerability in Sound Forge Pro 10.0b Build 474 allows local users to gain privileges via a Trojan horse MtxParhVegasPreview.dll file in the current working directory, as demonstrated by a directory that contains a .sfw file. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.1%—Gforgegroup Gforge14/2/201216/6/2026
SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)0.98%💥 ExploitNinjaforge Ninjamonials1/11/201116/6/2026
SQL injection vulnerability in the NinjaMonials (com_ninjamonials) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a display action to index.php.
ModificadaMedia (6.8)1.5%—Jasperforge Jasperreports Server Community Project20/9/201116/6/2026
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.
ModificadaMedia (4)1.2%—IBM Rational Build Forge8/9/201116/6/2026
IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu.
ModificadaBaja (2.1)0.38%—Rubyforge Rubygem-sqlite3Novell Suse Linux Enterprise13/5/201116/6/2026
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
ModificadaMedia (5)1.1%—IBM Rational Build Forge28/4/201116/6/2026
IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
ModificadaMedia (4.3)1.2%—IBM Rational Build Forge16/2/201116/6/2026
Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)11%💥 ExploitAlexej Kryukov Fontforge7/12/201016/6/2026
Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long CHARSET_REGISTRY header in a BDF font file.
ModificadaAlta (7.5)0.93%💥 ExploitJooforge COM Gamesbox12/7/201016/6/2026
SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a consoles action to index.php.
ModificadaAlta (9.3)5.8%💥 ExploitMoreforge Moreamp24/6/201016/6/2026
Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).
ModificadaMedia (5)14%💥 ExploitJooforge COM Jukebox12/4/201016/6/2026
Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)0.83%💥 ExploitMamboforge COM Mosres4/12/200916/6/2026
Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter…
ModificadaBaja (3.3)0.31%—Gforge4/12/200916/6/2026
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.
ModificadaAlta (7.5)1.7%—Gforge24/11/200916/6/2026
SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (4.3)1.7%—Gforge24/11/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.7%—Gforge24/11/200916/6/2026
Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.
ModificadaAlta (7.5)0.91%💥 ExploitNinjaforge COM Ninjamonials18/11/200916/6/2026
SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php.
ModificadaAlta (10)2.0%—Oxidforge Oxid EshopOxidforge Oxid Eshop4.0.0.2 149679/9/200916/6/2026
Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain administrator privileges and access the shop backend via a crafted parameter.
ModificadaAlta (7.5)2.3%💥 ExploitGforge19/2/200916/6/2026
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.
ModificadaAlta (7.5)1.3%💥 ExploitGforge19/2/200916/6/2026
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
ModificadaAlta (7.5)1.3%💥 ExploitGforge19/2/200916/6/2026
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
ModificadaMedia (4.3)1.0%—Sourceforge WOW Raid Manager18/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM) before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Orbitaley — Vulnerabilidades