Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.7% | — | Adobe Campaign | 15/2/2017 | 17/6/2026 | Adobe Campaign versions 16.4 Build 8724 and earlier have a cross-site scripting (XSS) vulnerability. | |
| Modificada | Crítica (9.1) | 2.8% | — | Adobe Campaign | 15/2/2017 | 17/6/2026 | Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability. | |
| Modificada | Media (5.4) | 0.70% | — | IBM Campaign | 1/2/2017 | 17/6/2026 | IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An… | |
| Modificada | Media (6.8) | 0.64% | — | Campaign Monitor Project Campaign Monitor | 15/6/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in includes/campaignmonitor_lists.admin.inc in the Campaign Monitor module 7.x-1.0 for Drupal allow remote attackers to hijack the authentication of users for requests that (1) enable list subscriptions via a request to… | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Champak - Hindi | 21/10/2014 | 17/6/2026 | The Champak - Hindi (aka com.magzter.champakhindi) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Paulalexanderformayor Paul Alexander Campaign | 16/10/2014 | 17/6/2026 | The Paul Alexander Campaign (aka hr.apps.n51261427) application 4.5.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.1% | — | Arialsoftware Campaign Enterprise | 14/8/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to execute arbitrary SQL commands via the (1) SerialNumber field to activate.asp or (2) UID field to User-Edit.asp. | |
| Modificada | Media (4.3) | 1.9% | — | Teampass | 7/8/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in items.php in TeamPass before 2.1.20 allow remote attackers to inject arbitrary web script or HTML via the group parameter, which is not properly handled in a (1) hid_cat or (2) open_folder form element, or (3) id parameter, which is not properly handled in the… | |
| Modificada | Alta (7.5) | 2.1% | — | Teampass | 7/8/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL commands via the login parameter in a (1) send_pw_by_email or (2) generate_new_password action in sources/main.queries.php; iDisplayStart parameter to (3) datatable.logs.php or (4) a file in… | |
| Modificada | Alta (7.5) | 2.6% | — | Teampass | 7/8/2014 | 17/6/2026 | TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a file that calls the session_start function before checking the CPM key, as demonstrated by a request to sources/upload/upload.files.php. | |
| Modificada | Alta (7.5) | 2.6% | — | Teampass | 7/8/2014 | 17/6/2026 | TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request to index.php or (2) "change_user_language" request to sources/main.queries.php. | |
| Modificada | Media (4.3) | 1.2% | — | Trexart Campaignmonitor | 31/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the… | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Teampass | 22/4/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sources/users.queries.php in TeamPass before 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the login parameter in an add_new_user action. | |
| Modificada | Media (6.5) | 2.0% | — | Apache Rampart/c | 2/6/2011 | 16/6/2026 | The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730. | |
| Modificada | Media (5) | 1.4% | — | Unica Affinium Campaign | 26/8/2009 | 16/6/2026 | Campaign/CampaignListener in the listener server in Unica Affinium Campaign 7.2.1.0.55 allows remote attackers to cause a denial of service (server crash) via a crafted length field that triggers (1) connection exhaustion or (2) memory allocation failure. | |
| Modificada | Media (6.8) | 1.5% | — | Unica Affinium Campaign | 26/8/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to (1) create arbitrary directories or files via a .. (dot dot) in the folder name in the new folder functionality or (2) list arbitrary files via a crafted request to Campaign/CampaignListener. | |
| Modificada | Media (4.3) | 1.8% | — | Unica Affinium Campaign | 26/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to inject arbitrary web script or HTML via a Javascript event in the (1) url, (2) PageName, and (3) title parameters in a CustomBookMarkLink action to Campaign/Campaign; (4) a Javascript event in the… | |
| Modificada | Media (4.3) | 1.1% | — | Activecampaign Triolive | 13/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Activecampaign Triolive | 13/11/2008 | 16/6/2026 | SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_id parameter to index.php. | |
| Modificada | Alta (7.2) | 0.39% | — | Ampache | 4/9/2008 | 16/6/2026 | gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file. | |
| Modificada | Media (6.8) | 1.5% | — | Ampache | 20/8/2007 | 16/6/2026 | Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (6.8) | 1.3% | — | Ampache | 20/8/2007 | 16/6/2026 | SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match parameter. NOTE: some details are obtained from third party information. | |
| Modificada | Media (6.5) | 1.3% | — | Activecampaign 1-2-all Broadcast Email | 11/5/2007 | 16/6/2026 | Incomplete blacklist vulnerability in filemanager/browser/default/connectors/php/config.php in the FCKeditor module, as used in ActiveCampaign 1-2-All (aka 12All) 4.50 through 4.53.13, and possibly other products, allows remote authenticated administrators to upload and possibly execute .php4 and .php5 files via… | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Activecampaign Knowledgebuilder | 15/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131. | |
| Modificada | Alta (7.5) | 1.6% | — | Ampache | 3/11/2006 | 16/6/2026 | Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restrictions and gain guest access. |