Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.6%—Opmantek Open-audit13/9/201917/6/2026
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
ModificadaMedia (6.5)4.3%—SqliteNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Oncommand Insight+169/9/201917/6/2026
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
ModificadaMedia (6.1)0.91%—Content Audit Project Content Audit21/8/201917/6/2026
The content-audit plugin before 1.9.2 for WordPress has XSS.
ModificadaAlta (7.8)0.47%—Netwrix Auditor12/8/201917/6/2026
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to that directory) does not perform proper impersonation, and thus the target file will have the same permissions as the…
ModificadaMedia (4.9)3.4%—OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+526/7/201917/6/2026
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from…
ModificadaMedia (5.4)0.64%—Chartered Accountant \ Auditor Website Project6/6/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.
ModificadaMedia (6.5)1.5%—Jenkins Audit TO Database4/4/201917/6/2026
A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
ModificadaMedia (6.5)1.3%—Jenkins Audit TO Database4/4/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
ModificadaAlta (8.8)1.3%—Jenkins Audit TO Database4/4/201917/6/2026
Jenkins Audit to Database Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaMedia (6.5)1.4%—Chartered Accountant \ Auditor Website Project21/3/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
ModificadaMedia (6.5)1.6%—Chartered Accountant \ Auditor Website Project21/3/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field.
ModificadaMedia (5.4)0.65%—Chartered Accountant \ Auditor Website Project21/3/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.
ModificadaAlta (7.5)6.7%—Zohocorp Manageengine Adaudit Plus13/12/201817/6/2026
Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Name' field when adding a new domain.
ModificadaAlta (7.7)1.0%—Oracle Retail Sales Audit17/10/201817/6/2026
Vulnerability in the Oracle Retail Sales Audit component of Oracle Retail Applications (subcomponent: Operational Insights). Supported versions that are affected are 15.0 and 16.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Sales Audit.…
ModificadaMedia (5.4)0.65%—Opmantek Open-audit19/9/201817/6/2026
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
ModificadaAlta (8.8)0.51%—Chartered Accountant \ Auditor Website Project10/8/201817/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.
ModificadaMedia (6.1)41%💥 ExploitOpmantek Open-audit25/7/201817/6/2026
Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.
ModificadaMedia (6.1)1.0%—Chartered Accountant \ Auditor Website Project9/7/201817/6/2026
PHP Scripts Mall Auditor Website 2.0.1 has XSS via the lastname or firstname parameter.
ModificadaMedia (5.4)1.9%💥 ExploitOpmantek Open-audit6/7/201817/6/2026
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.
ModificadaCrítica (9.8)17%—Zohocorp Manageengine Adaudit Plus29/5/201817/6/2026
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
ModificadaAlta (7.8)16%💥 ExploitDevicelock Plug AND Play Auditor10/5/201817/6/2026
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
ModificadaMedia (5.4)1.8%💥 ExploitOpmantek Open-audit10/5/201817/6/2026
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section.
ModificadaMedia (6.8)2.7%💥 ExploitOpen-audit19/4/201817/6/2026
Open-AudIT before 2.2 has CSV Injection.
ModificadaMedia (5.4)1.1%💥 ExploitOpen-audit12/4/201817/6/2026
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section (via the "Name (display)" field to the…
ModificadaAlta (8.8)0.84%—Wpsecurityauditlog WP Security Audit LOG6/4/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.