Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 4.2% | — | Quest Kace Desktop Authority | 22/12/2021 | 17/6/2026 | Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery. | |
| Modificada | Crítica (9.8) | 0.87% | — | Quest Kace Desktop Authority | 22/12/2021 | 17/6/2026 | An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of… | |
| Modificada | Media (5.5) | 3.0% | — | Quest Kace Desktop Authority | 22/12/2021 | 17/6/2026 | XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285. | |
| Modificada | Media (5.4) | 0.62% | — | Wpkube About Author BOX | 29/11/2021 | 17/6/2026 | The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks. | |
| Modificada | Media (4.8) | 1.1% | — | Author BIO BOX Project Author BIO BOX | 15/10/2021 | 17/6/2026 | The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-author-bio-box-admin.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in… | |
| Modificada | Media (5.4) | 1.8% | 💥 PoC | WP Html Author BIO Project WP Html Author BIO | 11/10/2021 | 17/6/2026 | The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site… | |
| Modificada | Alta (7.5) | 65% | 💥 Exploit | Powerdns Authoritative Server | 30/7/2021 | 17/6/2026 | PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception. | |
| Modificada | Alta (7.8) | 0.57% | — | Microsoft .net Education Bundle SDK Install ToolMicrosoft .net Install Tool FOR Extension Authors | 14/7/2021 | 10/8/2026 | Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability | |
| Modificada | Media (4.3) | 0.88% | — | Jenkins Role-based Authorization Strategy | 18/3/2021 | 17/6/2026 | An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders. | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins Matrix Authorization Strategy | 18/3/2021 | 17/6/2026 | An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders. | |
| Modificada | Media (5.4) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseDirs.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.6% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Reports/index.jsp file via the by parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.6% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/index.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (5.4) | 1.2% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the Error.jsp file via the err parameter (or indirectly via the cpr, tcp, or abs parameter). NOTE: This vulnerability only affects products that are no longer supported by… | |
| Modificada | Media (5.4) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the ReportPreview.do file via the referer parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.5) | 0.69% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafted link to the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (5.4) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (5.4) | 1.2% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.6% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Search/index.jsp file via the added parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the cConn.jsp file via the ur parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Crítica (9.8) | 1.9% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the PolicyAuthority/Common/FolderControl.jsp file via the unqID parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the initFile.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Role-based Authorization Strategy | 8/10/2020 | 17/6/2026 | Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuration. | |
| Modificada | Crítica (9.8) | 3.2% | — | Powerdns Authoritative | 2/10/2020 | 17/6/2026 | An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might be able to cause a double-free, leading to a crash or possibly arbitrary code execution. by sending crafted queries with a GSS-TSIG signature. |