Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.56% | — | AgoraAI | 6/8/2026 | 12/8/2026 | Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | |
| Analizada | Crítica (9.8) | 0.40% | — | Linagora Twake | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223. | |
| Analizada | Alta (8.8) | 0.36% | — | Linagora Twake | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attackers to execute arbitrary code. | |
| Analizada | Media (6.1) | 0.21% | — | Linagora Twake | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sensitive information and execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.43% | — | Agora-project | 15/1/2026 | 17/6/2026 | File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions. | |
| Modificada | Media (6.1) | 0.22% | — | Agora-project | 15/1/2026 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors. | |
| Analizada | Alta (8.8) | 0.40% | — | Agora-project | 15/1/2026 | 17/6/2026 | File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile action. | |
| Analizada | Alta (7.5) | 0.89% | — | Agora-project | 15/1/2026 | 17/6/2026 | Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read. | |
| Aplazada | Media (6.4) | 0.25% | — | Agora Foundation Agora Fall23-alpha1AIRepublique Francaise AgoraAI | 7/8/2025 | 17/6/2026 | In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG. | |
| Aplazada | Media (6.4) | 0.24% | — | Republique Francaise AgoraAI | 7/8/2025 | 17/6/2026 | In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js. | |
| Aplazada | Media (6.4) | 0.24% | — | Republique Francaise AgoraAI | 7/8/2025 | 17/6/2026 | In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManager.js. | |
| Aplazada | Alta (7.1) | 0.37% | — | Agora32 Maniac SEOAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agora32 Maniac SEO maniac-seo allows Reflected XSS.This issue affects Maniac SEO: from n/a through <= 2.0. | |
| Modificada | Crítica (9.8) | 0.59% | — | Linagora Twake | 7/11/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223. | |
| Modificada | Crítica (9.8) | 0.62% | 💥 PoC | Linagora Twake | 27/3/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0. | |
| Modificada | Media (5.4) | 56% | — | Linagora Twake | 1/1/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+. | |
| Modificada | Media (5.9) | 6.3% | — | Agora Video Software Development KIT | 17/2/2021 | 17/6/2026 | Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic. | |
| Modificada | Alta (7.5) | 2.8% | — | Linagora Hublin | 23/7/2019 | 17/6/2026 | LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact is: The vulnerability allows an attacker to access any file (with a fixed extension) on the server. The component is: A web-view renderer; details here:… | |
| Modificada | Media (6.1) | 0.83% | — | Agora-project | 9/3/2017 | 17/6/2026 | XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack. | |
| Modificada | Media (6.1) | 0.83% | — | Agora-project | 9/3/2017 | 17/6/2026 | XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack. | |
| Modificada | Media (6.1) | 0.83% | — | Agora-project | 9/3/2017 | 17/6/2026 | XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack. | |
| Modificada | Media (6.1) | 0.83% | — | Agora-project | 9/3/2017 | 17/6/2026 | XSS in Agora-Project 3.2.2 exists with an index.php?disconnect=1&msgNotif[]=[XSS] attack. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | W-agora | 5/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the bn parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | W-agora | 5/10/2011 | 16/6/2026 | Directory traversal vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bn parameter. | |
| Modificada | Media (6.8) | 0.57% | — | K-factor Agoracart | 4/1/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in AgoraCart 5.2.005 and 5.2.006 and AgoraCart GOLD 5.5.005 allow remote attackers to hijack the authentication of administrators for requests that (1) modify a .htaccess file via an unspecified request to protected/manager.cgi or (2) change the password of an… | |
| Modificada | Media (6.8) | 5.9% | 💥 Exploit | Jvitals COM Agora | 3/9/2009 | 16/6/2026 | Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php. |