Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.80%—Rocketgenius Gravityforms20/1/202117/6/2026
A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
ModificadaMedia (5.3)11%💥 ExploitRocket.chat8/1/202117/6/2026
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
ModificadaAlta (8.1)0.97%—Rocket31/12/202017/6/2026
An issue was discovered in the rocket crate before 0.4.5 for Rust. LocalRequest::clone creates more than one mutable references to the same object, possibly causing a data race.
ModificadaCrítica (9.8)1.6%—Rocket.chat30/12/202017/6/2026
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.
ModificadaMedia (6.1)2.8%—Rocket.chat18/8/202017/6/2026
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
ModificadaAlta (8.8)1.2%—Wpsocialrocket Social Sharing27/7/202017/6/2026
Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (7.5)1.8%—Rocketgenius Gravityforms2/6/202017/6/2026
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
ModificadaMedia (5.3)3.0%💥 PoCApache Rocketmq14/5/202017/6/2026
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users…
ModificadaMedia (6.1)4.0%💥 ExploitRocket.chat21/10/201917/6/2026
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
ModificadaAlta (7.5)1.2%—Rocket Coin Project Rocket Coin12/7/201817/6/2026
An integer overflow vulnerability exists in the function multiTransfer of Rocket Coin (XRC), an Ethereum token smart contract. An attacker could use it to set any user's balance.
ModificadaMedia (5.4)0.62%—Rocket.chat11/7/201817/6/2026
A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username unescaped via…
ModificadaMedia (6.1)0.76%—Rocket.chat11/7/201817/6/2026
An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the secret token of every user and also admins…
ModificadaAlta (7.5)27%💥 ExploitRedhat CloudformsRedhat Enterprise LinuxSprockets Project SprocketsDebian Linux26/6/201817/6/2026
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production.…
ModificadaCrítica (9.8)1.7%—Rocket.chat3/1/201817/6/2026
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
ModificadaAlta (7.5)3.3%—Wp-rocket26/7/201717/6/2026
In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00.../.%00.../ attack.
ModificadaMedia (6.1)0.73%—Rocketchat Rocket.chat17/7/201717/6/2026
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.
ModificadaMedia (5)3.9%—Sprockets Project Sprockets8/11/201417/6/2026
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before…
ModificadaAlta (10)73%💥 ExploitRocketsoftware Rocket Servergraph7/8/201417/6/2026
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to (1) create arbitrary files via a .. (dot dot) in the query parameter in a writeDataFile action to the fileRequestor servlet, execute arbitrary files via a .. (dot dot) in the…
ModificadaAlta (10)3.1%—Rocketsoftware Rocket Servergraph11/6/201417/6/2026
The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands via a (1) auth, (2) auth_session, (3) auth_simple, (4) add, (5) add_flat, (6) remove, (7) set_pwd, (8) add_permissions, (9) revoke_permissions, (10) runAsync, or (11)…
ModificadaAlta (7.5)0.96%💥 ExploitRockettheme COM Rokmodule19/4/201016/6/2026
SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the module parameter to index.php. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)2.3%💥 ExploitRockettheme COM Rokmodule19/4/201016/6/2026
SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter in a raw action to index.php.
ModificadaMedia (6.8)11%💥 ExploitRockettheme COM Rokdownloads23/3/201016/6/2026
Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
ModificadaMedia (5)1.5%—Rocketeer.dip Sisapilocation26/2/200916/6/2026
Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function."
ModificadaMedia (5)2.0%—Total PC Solutions PHP Rocket Add-in28/12/200116/6/2026
Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
Orbitaley — Vulnerabilidades