Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.13% | — | Google/apple Exposure Notifications | 28/4/2021 | 17/6/2026 | GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android allows attackers to obtain sensitive information, such as a user's location history, in-person social graph, and (sometimes) COVID-19 infection status, because Rolling Proximity Identifiers and MAC addresses are written to the Android system… | |
| Modificada | Alta (8.8) | 0.72% | — | Google Exposure Notifications Verification Server | 31/3/2021 | 17/6/2026 | A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create another user with higher privileges than their own. This occurs… | |
| Modificada | Baja (3.3) | 0.34% | — | Jenkins SMS Notification | 8/10/2020 | 17/6/2026 | Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (5.9) | 2.5% | — | Exposure Notifications Project Exposure Notifications | 7/10/2020 | 17/6/2026 | An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications on Android and iOS. The encrypted metadata block with a TX value lacks a checksum, allowing bitflipping to amplify a contamination attack. This can cause metadata deanonymization… | |
| Modificada | Media (5.7) | 0.32% | — | Apple Exposure NotificationsGoogle Exposure Notifications | 30/9/2020 | 17/6/2026 | An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or disproving an exposure notification, because of the persistent state of… | |
| Modificada | Media (4.3) | 1.1% | — | Infosysta In-app & Desktop Notifications | 1/11/2019 | 17/6/2026 | An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects (with authentication as a Jira user, but without authorization for specific projects) via the plugins/servlet/nfj/NotificationSettings URI. | |
| Modificada | Media (5.3) | 1.6% | — | Infosysta In-app & Desktop Notifications | 1/11/2019 | 17/6/2026 | An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI. | |
| Modificada | Media (5.3) | 1.6% | — | Infosysta In-app & Desktop Notifications | 31/10/2019 | 17/6/2026 | An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira usernames without authentication/authorization via the plugins/servlet/nfj/UserFilter?searchQuery=@ URI. | |
| Modificada | Alta (7.5) | 2.1% | — | Infosysta In-app & Desktop Notifications | 31/10/2019 | 17/6/2026 | An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These notifications are then no longer displayed to the… | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Pushover Notifications | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (6.5) | 0.93% | — | Jenkins Mattermost Notification | 23/10/2019 | 17/6/2026 | Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file and job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (5.4) | 1.1% | — | Onesignal-free-web-push-notifications | 30/8/2019 | 17/6/2026 | The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter. | |
| Modificada | Media (6.5) | 0.38% | — | Google Cloud Messaging Notification | 7/8/2019 | 17/6/2026 | Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Alta (7.1) | 1.1% | — | Jenkins Slack Notification | 28/3/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (7.5) | 1.4% | — | Jenkins Slack Notification | 28/3/2019 | 17/6/2026 | A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Crítica (9.8) | 1.2% | — | Icanstudioz Firebase Push Notification ON IOS / FCM + Advance Admin Panel | 10/7/2018 | 17/6/2026 | The "Firebase Cloud Messaging (FCM) + Advance Admin Panel" component supporting Firebase Push Notification on iOS (through 2017-10-26) allows SQL injection via the /advance_push/public/login username parameter. | |
| Modificada | Alta (8.8) | 6.5% | — | Adobe Push Notifications | 19/5/2018 | 17/6/2026 | Adobe PhoneGap Push Plugin versions 1.8.0 and earlier have an exploitable Same-Origin Method Execution vulnerability. Successful exploitation could lead to JavaScript code execution in the context of the PhoneGap app. | |
| Modificada | Media (4.4) | 0.62% | — | Alertus Desktop Notification FOR OS X | 26/6/2016 | 17/6/2026 | Alertus Desktop Notification before 2.9.31.1710 on OS X uses weak permissions for configuration files and unspecified other files, which allows local users to suppress emergency notifications or change content via standard filesystem operations. | |
| Modificada | Media (6.8) | 0.96% | — | DVS Custom Notification Project DVS Custom Notification | 10/4/2014 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS Custom Notification plugin 1.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change application settings or (2) conduct cross-site scripting (XSS) attacks. | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Instant Payment NotificationZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, a different vulnerability than… | |
| Modificada | Media (6.8) | 43% | 💥 Exploit | Symantec Altiris Deployment SolutionSymantec Altiris Notification ServerSymantec Management Platform | 7/3/2011 | 16/6/2026 | The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute… | |
| Modificada | Media (4.3) | 0.37% | — | Symantec Altiris Notification Server | 2/2/2010 | 16/6/2026 | The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute… | |
| Modificada | Alta (9.3) | 40% | 💥 Exploit | Symantec Altiris Deployment SolutionSymantec Altiris Management PlatformSymantec Altiris Notification Server | 25/11/2009 | 16/6/2026 | Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long… |