Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)81%—Articatech Artica Proxy21/3/202417/6/2026
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
AnalizadaAlta (7.5)45%—Articatech Artica Proxy21/3/202417/6/2026
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web application attempts to prevent local file…
AnalizadaCrítica (9.8)17%—Articatech Artica Proxy5/3/202417/6/2026
Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security issues associated with exposing this…
AnalizadaCrítica (9.8)0.93%—Articatech Artica Proxy5/3/202417/6/2026
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.
ModificadaMedia (6.1)1.6%—Articatech Artica Proxy24/8/202217/6/2026
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
ModificadaCrítica (9.8)2.6%—Articatech Artica Proxy5/5/202217/6/2026
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
ModificadaMedia (6.1)1.8%—Articatech Artica Proxy20/7/202017/6/2026
An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System Events, Proxy Events, Proxy Objects, and Firewall objects.
ModificadaAlta (7.5)2.2%—Articatech Artica Proxy20/7/202017/6/2026
An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.
ModificadaMedia (6.1)2.5%—Articatech Artica Proxy15/7/202017/6/2026
An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Address, Group Name, MYSQL Server, Database, MYSQL Username, Group Name, and Task Description fields.
ModificadaCrítica (9.8)9.3%—Articatech Artica Proxy22/6/202017/6/2026
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.
ModificadaAlta (7.5)54%—Articatech Artica Proxy22/6/202017/6/2026
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
ModificadaAlta (7.2)2.9%—Articatech Artica Proxy22/3/202017/6/2026
Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field.
ModificadaAlta (7.2)2.8%—Articatech Artica Proxy1/2/201917/6/2026
Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin and ldap_password fields, using these credentials at logon.php, and then entering the commands in the admin.index.php command-line field.
ModificadaCrítica (9)8.7%—Articatech Artica Proxy7/12/201717/6/2026
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.