Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Opmantek Open-audit | 13/9/2019 | 17/6/2026 | The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field. | |
| Modificada | Media (6.5) | 4.3% | — | SqliteNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Oncommand Insight+16 | 9/9/2019 | 17/6/2026 | In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner." | |
| Modificada | Media (6.1) | 0.91% | — | Content Audit Project Content Audit | 21/8/2019 | 17/6/2026 | The content-audit plugin before 1.9.2 for WordPress has XSS. | |
| Modificada | Alta (7.8) | 0.47% | — | Netwrix Auditor | 12/8/2019 | 17/6/2026 | Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to that directory) does not perform proper impersonation, and thus the target file will have the same permissions as the… | |
| Modificada | Media (4.9) | 3.4% | — | OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 26/7/2019 | 17/6/2026 | An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from… | |
| Modificada | Media (5.4) | 0.64% | — | Chartered Accountant \ Auditor Website Project | 6/6/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field. | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Audit TO Database | 4/4/2019 | 17/6/2026 | A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Audit TO Database | 4/4/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Audit TO Database | 4/4/2019 | 17/6/2026 | Jenkins Audit to Database Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Media (6.5) | 1.4% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. | |
| Modificada | Media (6.5) | 1.6% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field. | |
| Modificada | Media (5.4) | 0.65% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field. | |
| Modificada | Alta (7.5) | 6.7% | — | Zohocorp Manageengine Adaudit Plus | 13/12/2018 | 17/6/2026 | Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Name' field when adding a new domain. | |
| Modificada | Alta (7.7) | 1.0% | — | Oracle Retail Sales Audit | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle Retail Sales Audit component of Oracle Retail Applications (subcomponent: Operational Insights). Supported versions that are affected are 15.0 and 16.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Sales Audit.… | |
| Modificada | Media (5.4) | 0.65% | — | Opmantek Open-audit | 19/9/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field. | |
| Modificada | Alta (8.8) | 0.51% | — | Chartered Accountant \ Auditor Website Project | 10/8/2018 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php. | |
| Modificada | Media (6.1) | 41% | 💥 Exploit | Opmantek Open-audit | 25/7/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name. | |
| Modificada | Media (6.1) | 1.0% | — | Chartered Accountant \ Auditor Website Project | 9/7/2018 | 17/6/2026 | PHP Scripts Mall Auditor Website 2.0.1 has XSS via the lastname or firstname parameter. | |
| Modificada | Media (5.4) | 1.9% | 💥 Exploit | Opmantek Open-audit | 6/7/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Adaudit Plus | 29/5/2018 | 17/6/2026 | Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection. | |
| Modificada | Alta (7.8) | 16% | 💥 Exploit | Devicelock Plug AND Play Auditor | 10/5/2018 | 17/6/2026 | DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH). | |
| Modificada | Media (5.4) | 1.8% | 💥 Exploit | Opmantek Open-audit | 10/5/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section. | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | Open-audit | 19/4/2018 | 17/6/2026 | Open-AudIT before 2.2 has CSV Injection. | |
| Modificada | Media (5.4) | 1.1% | 💥 Exploit | Open-audit | 12/4/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section (via the "Name (display)" field to the… | |
| Modificada | Alta (8.8) | 0.84% | — | Wpsecurityauditlog WP Security Audit LOG | 6/4/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. |