Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.7%—Opentext Extended ECM18/1/202317/6/2026
A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files,…
ModificadaAlta (8.8)17%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports.
ModificadaAlta (7.5)17%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an…
ModificadaAlta (8.1)1.4%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user to delete arbitrary files on the server's local filesystem.
ModificadaAlta (8.8)1.6%—Opentext Extended ECM18/1/202317/6/2026
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie, without knowing the password.
ModificadaMedia (5.4)0.57%—Extendthemes Mesmerize Companion16/1/202317/6/2026
The Mesmerize Companion WordPress plugin before 1.6.135 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such…
ModificadaAlta (7.5)0.42%—Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Open Application Server13/1/202317/6/2026
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.
ModificadaAlta (7.5)0.63%—Checkpoint SSL Network Extender30/11/202217/6/2026
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.
ModificadaAlta (8.8)2.1%💥 PoCNextendweb Smart Slider 331/10/202217/6/2026
The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues when a user import (intentionally or not) a malicious file, and a suitable gadget chain is present on the site.
ModificadaCrítica (9.8)5.8%—Extended Keccak Code Package Project Extended Keccak Code PackageDebian LinuxFedoraproject FedoraPHP+421/10/202217/6/2026
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
ModificadaMedia (6.5)0.60%—Johnsoncontrols Metasys Extended Application AND Data Server7/10/202217/6/2026
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
ModificadaMedia (5.4)0.75%—Jenkins Dynamic Extended Choice Parameter27/7/202217/6/2026
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choice parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (5.3)0.68%—Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Open Application Server22/7/202217/6/2026
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
ModificadaMedia (6.5)0.71%—Admin Management Xtended Project Admin Management Xtended11/7/202217/6/2026
The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.
ModificadaMedia (5.4)0.80%—Jenkins Dynamic Extended Choice Parameter23/6/202217/6/2026
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (5.4)0.53%—Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Open Application Server15/6/202217/6/2026
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.
ModificadaMedia (5.4)0.57%—Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Open Application Server15/6/202217/6/2026
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface.
ModificadaAlta (7.5)0.95%—Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Open Application Server15/6/202217/6/2026
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.
ModificadaAlta (8.8)0.39%—Admin Management Xtended Project Admin Management Xtended15/6/202217/6/2026
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.
ModificadaMedia (5.4)0.30%—Static Page Extended Project Static Page Extended13/6/202217/6/2026
Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings
ModificadaAlta (7.5)1.5%—Verizon 4G LTE Network Extender Firmware2/6/202217/6/2026
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
ModificadaAlta (7.2)1.4%—Sooteway Wi-fi Range Extender Project Sooteway Wi-fi Range Extender20/5/202217/6/2026
SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.
ModificadaMedia (6.1)0.39%—Code Snippets Extended Project Code Snippets Extended17/5/202217/6/2026
Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code).
ModificadaMedia (5.4)0.40%—Code Snippets Extended Project Code Snippets Extended17/5/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to delete or to turn on/off snippets.
ModificadaAlta (8.8)0.96%—Code Snippets Extended Project Code Snippets Extended17/5/202217/6/2026
Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery.