Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

416 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.6%—Typo39/7/201917/6/2026
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
ModificadaAlta (7.8)1.8%—Typora17/5/201917/6/2026
Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by file:\\\ on macOS or Linux, or file://C| on Windows. This is different from CVE-2019-12137.
ModificadaAlta (7.8)6.5%💥 ExploitTypora16/5/201917/6/2026
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.
ModificadaAlta (7.5)3.9%—Typo39/5/201917/6/2026
TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.
ModificadaCrítica (9.8)5.4%—Typo3 PharstreamwrapperDebian LinuxFedoraproject FedoraDrupal+19/5/201917/6/2026
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
ModificadaCrítica (9.8)2.7%—Typo3 Pharstreamwrapper9/5/201917/6/2026
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
ModificadaMedia (6.1)1.7%—Typora31/1/201917/6/2026
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
ModificadaMedia (6.1)1.7%—Typora31/1/201917/6/2026
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
ModificadaMedia (6.1)1.9%—Typora25/1/201917/6/2026
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
ModificadaMedia (4.8)2.2%💥 PoCTypo38/4/201817/6/2026
The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.
ModificadaCrítica (9.8)2.2%💥 ExploitPhpcityportal29/10/201717/6/2026
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.
ModificadaMedia (5.4)1.3%—Typo320/10/201716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extension manager, or unspecified parameters to unknown…
ModificadaAlta (8.8)2.3%—Typo311/9/201717/6/2026
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.
ModificadaMedia (5.3)0.99%💥 PoCTypo317/3/201717/6/2026
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
ModificadaAlta (8.1)3.4%—Typo323/1/201717/6/2026
Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.
ModificadaMedia (6.1)1.1%—Typo323/1/201717/6/2026
Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.
ModificadaMedia (6.1)1.4%—Typo38/1/201617/6/2026
The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."
ModificadaMedia (5.4)0.64%—Typo38/1/201617/6/2026
Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.
ModificadaMedia (5.4)1.1%—Typo38/1/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.
ModificadaMedia (6.1)1.4%—Typo38/1/201617/6/2026
Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation.
ModificadaMedia (5.4)0.80%—Typo38/1/201617/6/2026
Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)1.1%—Typo38/1/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.
ModificadaBaja (3.5)2.0%—Typo316/9/201517/6/2026
The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2)…
ModificadaMedia (6.5)0.89%—Typo3 Neos1/4/201517/6/2026
TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors.
ModificadaBaja (2.6)1.5%—Typo3Debian Linux23/2/201517/6/2026
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty value.
Orbitaley — Vulnerabilidades