Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.51% | — | Sonicwall Netextender | 13/5/2022 | 17/6/2026 | A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system. | |
| Modificada | Alta (8.8) | 0.96% | — | Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Open Application Server | 6/5/2022 | 17/6/2026 | Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2. | |
| Modificada | Media (6.1) | 0.57% | — | Xtendtech Voice Logger | 2/5/2022 | 17/6/2026 | A reflected cross site scripting (XSS) vulnerability in Xtend Voice Logger 1.0 allows attackers to execute arbitrary web scripts or HTML, via the path of the error page. | |
| Modificada | Alta (8.8) | 0.97% | — | Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Open Application Server | 29/4/2022 | 17/6/2026 | Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator. | |
| Modificada | Crítica (9.8) | 1.0% | — | Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Open Application Server | 15/4/2022 | 17/6/2026 | Under certain circumstances the session token is not cleared on logout. | |
| Modificada | Media (5.4) | 0.66% | — | Jenkins Extended Choice Parameter | 12/4/2022 | 17/6/2026 | Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the name and description of Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.8) | 0.81% | — | Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Open Application Server | 7/4/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2. | |
| Modificada | Media (4.3) | 0.76% | — | Jenkins Extended Choice Parameter | 15/3/2022 | 17/6/2026 | A missing permission check in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. | |
| Modificada | Alta (8.8) | 0.58% | — | Jenkins Extended Choice Parameter | 15/3/2022 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to an attacker-specified URL. | |
| Modificada | Media (6.5) | 1.6% | — | Jenkins Extended Choice Parameter | 15/3/2022 | 17/6/2026 | Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission to read values from arbitrary JSON and Java properties files on the Jenkins controller. | |
| Modificada | Media (5.4) | 0.66% | — | Jenkins Extended Choice Parameter | 15/3/2022 | 17/6/2026 | Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of radio buttons or check boxes type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Crítica (9.8) | 1.4% | — | Object-extend Project Object-extend | 18/2/2022 | 17/6/2026 | The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend. | |
| Modificada | Alta (8.8) | 1.1% | — | Fortinet Fortiextender Firmware | 2/2/2022 | 17/6/2026 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands including special characters | |
| Modificada | Alta (7.2) | 1.5% | — | Acf-extended Advanced Custom Fields\ | 24/1/2022 | 17/6/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue | |
| Modificada | Crítica (9.8) | 1.5% | — | Eggjs Extend2 | 10/1/2022 | 17/6/2026 | The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge. | |
| Modificada | Media (4.3) | 0.54% | — | IBM Transformation Extender Advanced | 21/10/2021 | 17/6/2026 | IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be… | |
| Modificada | Alta (8.8) | 1.8% | — | Extendify Editorskit | 11/10/2021 | 17/6/2026 | The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code | |
| Modificada | Media (5.4) | 0.68% | — | Nextendweb Smart Slider | 14/6/2021 | 17/6/2026 | The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability.… | |
| Modificada | Media (5.3) | 23% | 💥 PoC | Checkpoint SSL Network Extender | 8/6/2021 | 17/6/2026 | SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access. | |
| Modificada | Crítica (9.8) | 3.0% | — | Js-extend Project Js-extend | 26/5/2021 | 17/6/2026 | Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Media (5.3) | 1.7% | 💥 Exploit | Sonicwall Netextender | 9/1/2021 | 17/6/2026 | SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier. | |
| Modificada | Alta (7.3) | 0.88% | — | Beckhoff Twincat Extended Automation Runtime | 19/11/2020 | 17/6/2026 | The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution… | |
| Modificada | Alta (7.8) | 0.55% | — | Sonicwall Netextender | 17/7/2020 | 17/6/2026 | SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 9.0.815 and earlier. | |
| Modificada | Crítica (9.8) | 2.5% | — | Node-extend Project Node-extend | 10/6/2020 | 17/6/2026 | node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execution. | |
| Modificada | Crítica (9.8) | 3.1% | — | Utils-extend Project Utils-extend | 3/4/2020 | 17/6/2026 | Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend. |