Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.6%—Openfind Mail200020/11/201917/6/2026
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments,…
ModificadaMedia (5.3)1.1%—Cksource Ckfinder26/9/201917/6/2026
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.
ModificadaAlta (7.5)1.5%—Cksource Ckfinder26/9/201917/6/2026
An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion,…
ModificadaMedia (6.1)1.0%—Findshorty Dwnldr16/9/201917/6/2026
The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.
ModificadaCrítica (9.8)2.4%—Cysteme-finder13/9/201917/6/2026
The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
ModificadaMedia (6.1)1.2%—Sunhater Kcfinder28/7/201917/6/2026
A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditorFuncNum parameter.
ModificadaAlta (7.8)0.32%—Cisco Findit Network ManagerCisco Findit Network Probe17/7/201917/6/2026
A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the presence of an account with static…
ModificadaMedia (6.1)1.2%—Openfind Mail200019/6/201917/6/2026
An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this).
ModificadaCrítica (9.8)97%💥 ExploitStd42 Elfinder26/2/201917/6/2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
ModificadaCrítica (9.8)2.0%—Themerig Find A Place CMS Directory16/2/201917/6/2026
Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter.
ModificadaAlta (7.7)1.1%—Std42 Elfinder14/1/201917/6/2026
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php.
ModificadaMedia (5.9)1.3%—Std42 Elfinder10/1/201917/6/2026
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.
ModificadaAlta (7.5)1.5%—Multitech Faxfinder3/10/201817/6/2026
Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points.
ModificadaAlta (7.5)1.2%—Ovation Findme26/8/201817/6/2026
Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for discovering the product's capabilities or purpose. This makes it easier for adversaries to detect the covert operation. Specifically, the product uses a…
ModificadaAlta (7.5)2.0%—Utahcityfinder Project Utahcityfinder7/6/201817/6/2026
utahcityfinder constructs lists of Utah cities with a certain prefix. utahcityfinder is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaCrítica (9.1)2.9%—Std42 Elfinder28/3/201817/6/2026
Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process. NOTE: this issue exists because of an…
ModificadaCrítica (9.1)2.9%—Std42 Elfinder28/3/201817/6/2026
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process.
ModificadaAlta (7.5)1.3%—Qnap Qfinder PRO5/3/201817/6/2026
QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further compromise the device.
ModificadaAlta (8.8)0.95%—Jenkins Findbugs23/1/201817/6/2026
Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
ModificadaAlta (7.5)0.60%—Huawei SmarthomeHuawei HiappHuawei HwparentcontrolHuawei Hwparentcontrolparent+1022/11/201717/6/2026
Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and…
ModificadaAlta (7.8)0.36%—Cisco Findit Network Discovery Utility16/11/201717/6/2026
A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to the device availability, confidentiality, and integrity, aka Insecure Library Loading. The vulnerability is due to the application…
ModificadaMedia (5.4)0.61%—Taxonomy Find Project Taxonomy Find6/11/201717/6/2026
Cross-site scripting (XSS) vulnerability in the Taxonomy Find module 6.x-2.x through 6.x-1.2 and 7.x-2.x through 7.x-1.0 in Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via taxonomy vocabulary and term names.
ModificadaCrítica (9.8)2.1%—Multitech Faxfinder30/9/201717/6/2026
MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP configuration. These credentials are retrieved by the system when the LDAP configuration page is opened and are embedded directly into the HTML source code in cleartext.
ModificadaAlta (7.8)0.36%—Cisco Findit Network Discovery Utility21/9/201717/6/2026
A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to device availability, confidentiality, and integrity. The vulnerability is due to the application loading a malicious copy of a specific,…
ModificadaMedia (6.5)1.7%—Cisco Findit Network Probe20/4/201717/6/2026
A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authenticated, remote attacker to download and view any system file by using the affected software. The vulnerability is due to the absence of role-based access control (RBAC) for…
Orbitaley — Vulnerabilidades