Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Typo3 | 9/7/2019 | 17/6/2026 | TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data. | |
| Modificada | Alta (7.8) | 1.8% | — | Typora | 17/5/2019 | 17/6/2026 | Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by file:\\\ on macOS or Linux, or file://C| on Windows. This is different from CVE-2019-12137. | |
| Modificada | Alta (7.8) | 6.5% | 💥 Exploit | Typora | 16/5/2019 | 17/6/2026 | Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note. | |
| Modificada | Alta (7.5) | 3.9% | — | Typo3 | 9/5/2019 | 17/6/2026 | TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick. | |
| Modificada | Crítica (9.8) | 5.4% | — | Typo3 PharstreamwrapperDebian LinuxFedoraproject FedoraDrupal+1 | 9/5/2019 | 17/6/2026 | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL. | |
| Modificada | Crítica (9.8) | 2.7% | — | Typo3 Pharstreamwrapper | 9/5/2019 | 17/6/2026 | PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism. | |
| Modificada | Media (6.1) | 1.7% | — | Typora | 31/1/2019 | 17/6/2026 | typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula. | |
| Modificada | Media (6.1) | 1.7% | — | Typora | 31/1/2019 | 17/6/2026 | typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula. | |
| Modificada | Media (6.1) | 1.9% | — | Typora | 25/1/2019 | 17/6/2026 | typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar. | |
| Modificada | Media (4.8) | 2.2% | 💥 PoC | Typo3 | 8/4/2018 | 17/6/2026 | The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Phpcityportal | 29/10/2017 | 17/6/2026 | PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter. | |
| Modificada | Media (5.4) | 1.3% | — | Typo3 | 20/10/2017 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extension manager, or unspecified parameters to unknown… | |
| Modificada | Alta (8.8) | 2.3% | — | Typo3 | 11/9/2017 | 17/6/2026 | Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code. | |
| Modificada | Media (5.3) | 0.99% | 💥 PoC | Typo3 | 17/3/2017 | 17/6/2026 | TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields. | |
| Modificada | Alta (8.1) | 3.4% | — | Typo3 | 23/1/2017 | 17/6/2026 | Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action. | |
| Modificada | Media (6.1) | 1.1% | — | Typo3 | 23/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark. | |
| Modificada | Media (6.1) | 1.4% | — | Typo3 | 8/1/2016 | 17/6/2026 | The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing." | |
| Modificada | Media (5.4) | 0.64% | — | Typo3 | 8/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field. | |
| Modificada | Media (5.4) | 1.1% | — | Typo3 | 8/1/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (6.1) | 1.4% | — | Typo3 | 8/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation. | |
| Modificada | Media (5.4) | 0.80% | — | Typo3 | 8/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 1.1% | — | Typo3 | 8/1/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Baja (3.5) | 2.0% | — | Typo3 | 16/9/2015 | 17/6/2026 | The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2)… | |
| Modificada | Media (6.5) | 0.89% | — | Typo3 Neos | 1/4/2015 | 17/6/2026 | TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors. | |
| Modificada | Baja (2.6) | 1.5% | — | Typo3Debian Linux | 23/2/2015 | 17/6/2026 | The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty value. |