Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 3.9% | 💥 Exploit | Microweber | 26/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. | |
| Modificada | Alta (7.5) | 1.4% | — | Microweber | 20/1/2022 | 17/6/2026 | Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Microweber | 20/1/2022 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11. | |
| Modificada | Media (5.4) | 0.73% | — | Microweber | 20/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. | |
| Modificada | Media (6.5) | 1.1% | — | Microweber | 20/1/2022 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11. | |
| Modificada | Media (6.1) | 0.92% | — | Crowcpp Crow | 13/1/2022 | 17/6/2026 | This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. This may lead to a Cross-site Scripting (XSS) vulnerability, assuming an attacker can influence the value entered into… | |
| Modificada | Alta (7.5) | 1.6% | — | Crowcpp Crow | 13/1/2022 | 17/6/2026 | This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the server. | |
| Modificada | Media (6.1) | 1.1% | — | Microweber | 19/10/2021 | 17/6/2026 | Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form. | |
| Modificada | Media (5.3) | 1.3% | — | Atlassian Crowd | 1/3/2021 | 17/6/2026 | The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check. | |
| Modificada | Alta (7.2) | 17% | 💥 Exploit | Microweber | 15/2/2021 | 17/6/2026 | A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with… | |
| Modificada | Alta (8.1) | 1.0% | — | Microweber | 9/11/2020 | 17/6/2026 | Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active. | |
| Modificada | Media (5.5) | 0.31% | — | Microweber | 9/11/2020 | 17/6/2026 | Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise. | |
| Modificada | Crítica (9.8) | 1.3% | — | Microweber | 9/11/2020 | 17/6/2026 | An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension. | |
| Modificada | Media (5.5) | 0.32% | — | Microweber | 9/11/2020 | 9/7/2026 | Microweber v1.1.18 is affected by no session expiry after log-out. | |
| Modificada | Alta (7.5) | 0.87% | — | Atlassian Crowd | 1/10/2020 | 17/6/2026 | Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Microweber | 16/7/2020 | 17/6/2026 | userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request. | |
| Modificada | Alta (7.8) | 0.46% | — | Microweber | 20/5/2020 | 17/6/2026 | Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file. | |
| Modificada | Crítica (9.8) | 1.3% | — | Trianglemicroworks Dnp3 Source Code Library | 15/4/2020 | 17/6/2026 | Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3.16.00 through 3.25.01. A specially crafted message may cause a stack-based buffer overflow. Authentication is not required to exploit this vulnerability. | |
| Modificada | Alta (7.5) | 2.6% | — | Trianglemicroworks Scada Data Gateway | 15/4/2020 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service condition due to a lack of proper validation of the length of user-supplied data, prior to copying it to a fixed-length stack-based buffer. Authentication is not required to… | |
| Modificada | Alta (7.5) | 2.5% | — | Trianglemicroworks Scada Data Gateway | 15/4/2020 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to disclose sensitive information due to the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. Authentication is not required to exploit… | |
| Modificada | Crítica (9.8) | 5.2% | — | Trianglemicroworks Scada Data Gateway | 15/4/2020 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type confusion condition. Authentication is not required to exploit this vulnerability. Only… | |
| Modificada | Alta (7.8) | 0.32% | — | Suse Openstack CloudSuse Openstack Cloud Crowbar | 3/4/2020 | 17/6/2026 | An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8, SUSE OpenStack Cloud Crowbar 9 allows root users on any crowbar managed node to cause become root on any other node. This issue affects: SUSE OpenStack Cloud 7… | |
| Modificada | Alta (7.5) | 2.4% | — | Atlassian Crowd | 6/2/2020 | 17/6/2026 | The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability. | |
| Modificada | Media (6.5) | 0.45% | — | Atlassian Crowd | 17/12/2019 | 17/6/2026 | Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default. | |
| Modificada | Media (4.3) | 1.3% | — | Atlassian Troubleshooting AND SupportAtlassian BambooAtlassian BitbucketAtlassian Confluence+4 | 8/11/2019 | 17/6/2026 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the… |