Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

47 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.56%—AgoraAI6/8/202612/8/2026
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
AnalizadaCrítica (9.8)0.40%—Linagora Twake9/3/202617/6/2026
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.
AnalizadaAlta (8.8)0.36%—Linagora Twake9/3/202617/6/2026
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attackers to execute arbitrary code.
AnalizadaMedia (6.1)0.21%—Linagora Twake9/3/202617/6/2026
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sensitive information and execute arbitrary code.
AnalizadaCrítica (9.8)0.43%—Agora-project15/1/202617/6/2026
File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.
ModificadaMedia (6.1)0.22%—Agora-project15/1/202617/6/2026
Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.
AnalizadaAlta (8.8)0.40%—Agora-project15/1/202617/6/2026
File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile action.
AnalizadaAlta (7.5)0.89%—Agora-project15/1/202617/6/2026
Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.
AplazadaMedia (6.4)0.25%—Agora Foundation Agora Fall23-alpha1AIRepublique Francaise AgoraAI7/8/202517/6/2026
In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.
AplazadaMedia (6.4)0.24%—Republique Francaise AgoraAI7/8/202517/6/2026
In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js.
AplazadaMedia (6.4)0.24%—Republique Francaise AgoraAI7/8/202517/6/2026
In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManager.js.
AplazadaAlta (7.1)0.37%—Agora32 Maniac SEOAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agora32 Maniac SEO maniac-seo allows Reflected XSS.This issue affects Maniac SEO: from n/a through <= 2.0.
ModificadaCrítica (9.8)0.59%—Linagora Twake7/11/202317/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
ModificadaCrítica (9.8)0.62%💥 PoCLinagora Twake27/3/202317/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.
ModificadaMedia (5.4)56%—Linagora Twake1/1/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.
ModificadaMedia (5.9)6.3%—Agora Video Software Development KIT17/2/202117/6/2026
Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic.
ModificadaAlta (7.5)2.8%—Linagora Hublin23/7/201917/6/2026
LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact is: The vulnerability allows an attacker to access any file (with a fixed extension) on the server. The component is: A web-view renderer; details here:…
ModificadaMedia (6.1)0.83%—Agora-project9/3/201717/6/2026
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.
ModificadaMedia (6.1)0.83%—Agora-project9/3/201717/6/2026
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack.
ModificadaMedia (6.1)0.83%—Agora-project9/3/201717/6/2026
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack.
ModificadaMedia (6.1)0.83%—Agora-project9/3/201717/6/2026
XSS in Agora-Project 3.2.2 exists with an index.php?disconnect=1&msgNotif[]=[XSS] attack.
ModificadaMedia (4.3)1.5%💥 ExploitW-agora5/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the bn parameter.
ModificadaAlta (7.5)2.4%💥 ExploitW-agora5/10/201116/6/2026
Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bn parameter.
ModificadaMedia (6.8)0.57%—K-factor Agoracart4/1/201016/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in AgoraCart 5.2.005 and 5.2.006 and AgoraCart GOLD 5.5.005 allow remote attackers to hijack the authentication of administrators for requests that (1) modify a .htaccess file via an unspecified request to protected/manager.cgi or (2) change the password of an…
ModificadaMedia (6.8)5.9%💥 ExploitJvitals COM Agora3/9/200916/6/2026
Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.
Orbitaley — Vulnerabilidades