Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.87% | — | Telligent Community | 23/10/2018 | 17/6/2026 | Telligent Community 6.x, 7.x, 8.x, 9.x before 9.2.10.11796, 10.1.x before 10.1.10.11792, and 10.2.x before 10.2.3.4725 has XSS via the Feed RSS widget. | |
| Modificada | Alta (7.8) | 5.6% | — | Microsoft Visual Studio Community | 26/6/2018 | 17/6/2026 | Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (8.8) | 1.1% | — | Invisioncommunity Invision Power Board | 20/3/2018 | 17/6/2026 | SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the cId parameter. | |
| Modificada | Crítica (9.8) | 8.3% | 💥 Exploit | Community Events Project Community Events | 7/9/2017 | 17/6/2026 | SQL injection vulnerability in WordPress Community Events plugin before 1.4. | |
| Modificada | Media (6.5) | 1.3% | — | Tibco Jasperreports Library Community EditionTibco Jasperreports Library FOR Activematrix BPMTibco Jasperreports ProfessionalTibco Jasperreports Server+5 | 29/6/2017 | 17/6/2026 | JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports Library for… | |
| Modificada | Media (5.9) | 0.48% | — | Csb-lamar Community State Bank-lamar | 16/6/2017 | 17/6/2026 | The "Community State Bank - Lamar Mobile Banking" by Community State Bank - Lamar app 3.0.3 -- aka community-state-bank-lamar-mobile-banking/id1083927885 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted… | |
| Modificada | Media (5.9) | 0.49% | — | Rivervalleycommunitybank Rvcb Mobile | 16/6/2017 | 17/6/2026 | The "RVCB Mobile" by RVCB Mobile Banking app 3.0.0 -- aka rvcb-mobile/id757928895 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.9) | 0.49% | — | Mononabank Middleton Community Bank Mobile | 16/6/2017 | 17/6/2026 | The "Middleton Community Bank Mobile Banking" by Middleton Community Bank app 3.0.0 -- aka middleton-community-bank-mobile-banking/id721843238 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted… | |
| Modificada | Media (5.9) | 0.49% | — | Meafinancial Community Banks Cb2go | 16/6/2017 | 17/6/2026 | The community-banks-cb2go/id445828071 app 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (8.1) | 1.5% | — | Invisioncommunity Invision Power Board | 11/5/2017 | 17/6/2026 | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power Board user and can be used to gain access to moderator/admin accounts. The primary cause is the… | |
| Modificada | Crítica (9.8) | 1.9% | — | Invisioncommunity Invision Power Board | 11/5/2017 | 17/6/2026 | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the "<>… | |
| Modificada | Media (6.1) | 1.2% | — | Invisioncommunity Invision Power Board | 11/5/2017 | 17/6/2026 | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a malicious announcement affecting any Invision Power Board user… | |
| Modificada | Media (6.5) | 1.7% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 24/4/2017 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Oracle PeopleSoft Products (subcomponent: Frameworks). The supported version that is affected is 9.2. Easily "exploitable" vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus… | |
| Modificada | Media (5.9) | 1.3% | — | Invisioncommunity Invision Power Board | 23/4/2017 | 17/6/2026 | Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation. | |
| Modificada | Alta (8.1) | 12% | 💥 Exploit | Invisioncommunity Invision Power BoardPHP | 12/7/2016 | 17/6/2026 | applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter. | |
| Modificada | Alta (7.8) | 1.4% | — | Invisioncommunity Invision Power Board | 4/9/2015 | 17/6/2026 | Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial of service (loop and memory consumption) via a crafted URL. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Wotlab Community Gallery | 12/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or HTML via the parameters[data][7][title] parameter in a saveImageData action to index.php/AJAXProxy. | |
| Modificada | Media (5) | 2.0% | 💥 Exploit | Alfresco Community Edition | 7/12/2014 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attackers to trigger outbound requests via a crafted URI in the url parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Invisioncommunity Invision Power BoardInvisionpower Invision Power Board | 3/12/2014 | 17/6/2026 | SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[] parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Androidcommunity Hector Leal | 20/10/2014 | 17/6/2026 | The Hector Leal (aka ad.hector.leal.com) application 13/08/14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Listener-interactive Kfai Community Radio | 4/10/2014 | 17/6/2026 | The KFAI Community Radio (aka com.skyblue.pra.kfai) application 2.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Communityfactory Selfie Camera -facial Beauty- | 9/9/2014 | 17/6/2026 | The Selfie Camera -Facial Beauty- (aka com.cfinc.cunpic) application 1.2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.1% | — | Invisioncommunity Invision Power Board | 28/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to admin/install/index.php. | |
| Modificada | Media (4.3) | 1.9% | — | Invisioncommunity Invision Power BoardInvisionpower Ip.nexus | 3/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded before 20140424, or IP.Nexus 1.5.x through 1.5.9, as downloaded before 20140424, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Redhat Jboss Community Application ServerRedhat Jboss Enterprise Application Platform | 28/10/2013 | 16/6/2026 | The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a… |