Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1025 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 32% | 💥 Exploit | Myprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts | 20/9/2023 | 17/6/2026 | MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php. | |
| Modificada | Crítica (9.8) | 0.81% | — | Blmodules Xmlfeeds PRO | 15/9/2023 | 17/6/2026 | Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds(). | |
| Modificada | Crítica (9.8) | 2.0% | — | Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+20 | 13/9/2023 | 17/6/2026 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | |
| Modificada | Alta (8.8) | 0.99% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with… | |
| Modificada | Crítica (9.1) | 0.56% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user. | |
| Modificada | Crítica (9.8) | 0.42% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless. | |
| Modificada | Alta (7.7) | 0.47% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services. | |
| Modificada | Alta (8.8) | 0.73% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and… | |
| Modificada | Media (6.5) | 0.33% | — | Cisco Video Phone 8875 FirmwareCisco IP Phone 6821 With Multiplatform FirmwareCisco IP Phone 6825 With Multiplatform FirmwareCisco IP Phone 6841 With Multiplatform Firmware+19 | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system. This… | |
| Modificada | Alta (7.8) | 1.2% | — | Keep-module-latest Project Keep-module-latest | 27/5/2023 | 17/6/2026 | All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. **Note:** To execute the code snippet and potentially exploit the vulnerability, the attacker needs to have the ability to run… | |
| Modificada | Crítica (9.8) | 0.77% | — | Rental Module Project Rental Module | 20/5/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass. This issue affects Rental Module: before 23.05.15. | |
| Modificada | Crítica (9.8) | 1.3% | — | Rental Module Project Rental Module | 20/5/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server. This issue affects Rental Module: before 23.05.15. | |
| Modificada | Media (4.3) | 0.59% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to create folders in arbitrary paths of the file system. See SEL Service… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (4.3) | 0.48% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to arbitrarily alter the content of a configuration file. See SEL Service Bulletin dated 2022-11-15 for more details. | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code.See SEL Service Bulletin… |