Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.14% | — | Revive AdserverAI | 20/7/2026 | 23/7/2026 | A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated… | |
| Analizada | Media (6.1) | 0.38% | — | Revive-adserver Revive Adserver | 26/6/2026 | 29/6/2026 | A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing user‑supplied input to be reflected without… | |
| Analizada | Media (4.3) | 0.29% | — | Revive-adserver Revive Adserver | 26/6/2026 | 29/6/2026 | A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an error, the associated session was not invalidated. As a result, the leaked session ID could be… | |
| Analizada | Media (5.4) | 0.34% | — | Revive-adserver Revive Adserver | 26/6/2026 | 29/6/2026 | A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is executed when an administrator uses the… | |
| Analizada | Alta (8.8) | 4.9% | — | Revive-adserver Revive Adserver | 26/6/2026 | 29/6/2026 | Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method. | |
| Analizada | Media (5.4) | 0.38% | — | Revive-adserver Revive Adserver | 26/6/2026 | 8/7/2026 | A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks. | |
| Analizada | Media (4.3) | 0.49% | — | Revive-adserver Revive Adserver | 26/6/2026 | 29/6/2026 | A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in Revive Adserver 6.0.7 and earlier. As a result, a low‑privileged user could link their trackers to campaigns owned by… | |
| Aplazada | Alta (8.8) | 0.58% | — | Revive AdserverAI | 23/6/2026 | 23/6/2026 | A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed during banner delivery. Input sanitisation… | |
| Aplazada | Media (5.4) | 0.34% | — | Revive AdserverAI | 23/6/2026 | 23/6/2026 | An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten solely based on banner edit permissions. The status field has been… | |
| Aplazada | Media (4.3) | 0.27% | — | Revive AdserverAI | 23/6/2026 | 23/6/2026 | A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities, leading to inconsistent ownership relationships. This issue was exploitable only in combination with CVE‑2026‑34917 or… | |
| Aplazada | Alta (8.8) | 0.65% | — | Revive AdserverAI | 23/6/2026 | 23/6/2026 | A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has… | |
| Aplazada | Media (6.1) | 0.26% | — | Revive AdserverAI | 23/6/2026 | 23/6/2026 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly… | |
| Aplazada | Alta (8.3) | 0.39% | — | Revive-adserver Revive AdserverAI | 23/6/2026 | 23/6/2026 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated. | |
| Aplazada | Media (4.3) | 0.27% | — | Revive AdserverAI | 23/6/2026 | 23/6/2026 | A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships.… | |
| Aplazada | Media (4.3) | 0.27% | — | Revive AdserverAI | 23/6/2026 | 23/6/2026 | A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent… | |
| Analizada | Media (6.1) | 0.20% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | El miembro de la comunidad de HackerOne Huynh Pham Thanh Luc (nigh7c0r3) ha informado de una vulnerabilidad de XSS reflejado en el script de entrega afr.php de Revive Adserver. Un atacante puede crear una URL específica que incluye una carga útil HTML en un parámetro. Si un administrador con sesión iniciada visita la… | |
| Analizada | Media (6.1) | 0.20% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | El miembro de la comunidad de HackerOne Patrick Lang (7yr) ha informado de una vulnerabilidad de XSS reflejado en el script banner-acl.php de Revive Adserver. Un atacante puede crear una URL específica que incluye una carga útil HTML en un parámetro. Si un administrador con sesión iniciada visita la URL, el HTML se… | |
| Analizada | Media (6.1) | 0.20% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | El miembro de la comunidad de HackerOne Patrick Lang (7yr) ha reportado una vulnerabilidad de XSS reflejado en los scripts 'banner-acl.php' y 'channel-acl.php' de Revive Adserver. Un atacante puede crear una URL específica que incluye una carga útil HTML en un parámetro. Si un administrador con sesión iniciada visita… | |
| Analizada | Media (6.5) | 0.27% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | El miembro de la comunidad de HackerOne Jad Ghamloush (0xjad) ha informado de una vulnerabilidad de omisión de autorización en el script `tracker-delete.php` de Revive Adserver. A los usuarios con permisos para eliminar rastreadores se les permite erróneamente eliminar rastreadores que pertenecen a otras cuentas. | |
| Analizada | Baja (2.7) | 0.25% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | El miembro de la comunidad de HackerOne Faraz Ahmed (PakCyberbot) ha informado de una inyección de cadena de formato en la configuración de Revive Adserver. Cuando se utilizan combinaciones de caracteres específicas en una configuración, la consola del usuario administrador podría deshabilitarse debido a un error… | |
| Modificada | Media (5.1) | 2.7% | — | Revive-adserver Revive Adserver | 17/12/2025 | 17/6/2026 | Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a malicious link to the banner-advanced.php endpoint with XSS payloads in prepend and append parameters to execute arbitrary JavaScript… | |
| Analizada | Media (5.4) | 0.24% | — | Aquaplatform Revive Adserver | 2/12/2025 | 17/6/2026 | El miembro de la comunidad de HackerOne Kassem S.(kassem_s94) ha informado que el manejo de nombres de usuario en Revive Adserver seguía siendo vulnerable a ataques de suplantación de identidad después de la corrección para CVE-2025-52672, a través de varias técnicas alternativas. La suplantación de identidad basada… | |
| Analizada | Media (6.1) | 0.41% | — | Revive-adserver Revive Adserver | 20/11/2025 | 25/9/2026 | Neutralización incorrecta de la entrada en Revive Adserver 6.0.0+ causa un ataque de XSS Reflejado en el script banner-zone.php. | |
| Analizada | Media (5.4) | 0.45% | — | Revive-adserver Revive Adserver | 20/11/2025 | 25/9/2026 | La neutralización inadecuada de la entrada en Revive Adserver 5.5.2 y 6.0.1 y versiones anteriores permite a las cuentas de administrador elaborar ataques XSS dirigidos a sus propios usuarios anunciantes. | |
| Analizada | Media (4.3) | 0.35% | — | Revive-adserver Revive Adserver | 20/11/2025 | 25/9/2026 | La revelación de información de depuración en el mensaje de error SQL en Revive Adserver 5.5.2 y 6.0.1 y versiones anteriores provoca que los usuarios no administradores adquieran información sobre las versiones de software, PHP y base de datos actualmente en uso. |