Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.70% | — | Invision CommunityAI | 7/6/2024 | 17/6/2026 | Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory… | |
| Aplazada | Media (6.3) | 0.78% | — | OtrsAIOtrs Community EditionAI | 6/6/2024 | 17/6/2026 | The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially leading to the execution of local code like Perl scripts. This issue… | |
| Aplazada | Crítica (9.4) | 12% | — | Ligowave UnityAILigowave PROAILigowave MimoAILigowave APC PropellerAI | 16/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through… | |
| Aplazada | Media (5.4) | 0.48% | — | ANT Media Server Community EditionAI | 14/5/2024 | 17/6/2026 | Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users. All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor… | |
| Aplazada | Crítica (10) | 1.00% | — | Uvdesk CommunityAI | 25/4/2024 | 17/6/2026 | Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3. | |
| Aplazada | Media (4.3) | 0.18% | — | Peepso CommunityAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.3.1.1. | |
| Aplazada | Alta (7.5) | 0.84% | 💥 PoC | Sheetjs Community EditionAI | 5/4/2024 | 17/6/2026 | SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS). | |
| Aplazada | Alta (7.1) | 0.36% | — | Uvdesk Community SkeletonAI | 2/4/2024 | 17/6/2026 | Improper Privilege Management in uvdesk/community-skeleton | |
| Aplazada | Media (5.3) | 0.44% | — | Peepso CommunityAI | 28/3/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.2.7.0. | |
| Aplazada | Media (5.3) | 0.51% | — | Peepso CommunityAI | 26/3/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.0.9.0. | |
| Modificada | Alta (7.5) | 0.56% | — | Steve-community Steve | 13/2/2024 | 17/6/2026 | SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions. | |
| Modificada | Media (5.4) | 0.29% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the affected user or carry out any actions that this user could perform, or to generally control the victim's browser. | |
| Modificada | Alta (7.8) | 0.64% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 0.64% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability execute commands with root privileges. | |
| Modificada | Media (6.5) | 0.35% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain unauthorized write access to the files stored on the server filesystem, with elevated privileges. | |
| Modificada | Alta (7.8) | 1.0% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 0.88% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 0.88% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the… | |
| Modificada | Alta (7.8) | 0.90% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of… | |
| Modificada | Media (6.5) | 0.42% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information. | |
| Modificada | Alta (7.8) | 0.84% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Modificada | Media (5.4) | 0.32% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Modificada | Alta (7.8) | 0.84% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an authenticated attacker to execute commands… | |
| Modificada | Alta (7.8) | 0.81% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges. | |
| Modificada | Alta (7.8) | 1.1% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges. |