Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.41% | — | Owasp DefectdojoAI | 23/7/2026 | 24/7/2026 | A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Alta (8.5) | 1.4% | — | KanadojoAIGithub ActionsAI | 11/6/2026 | 14/7/2026 | KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of patchNotesData.json, which are interpolated unsanitized into a child_process.execSync() call in the… | |
| Aplazada | Alta (8.5) | 0.69% | — | KanadojoAI | 11/6/2026 | 14/7/2026 | KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull request modifying… | |
| Aplazada | Baja (2.1) | 0.38% | — | Owasp DefectdojoAI | 30/4/2026 | 17/6/2026 | A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been publicly disclosed and… | |
| Analizada | Baja (2.1) | 0.71% | — | Owasp Defectdojo | 9/3/2026 | 17/6/2026 | A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQubeParser/MSDefenderParser. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Alta (8.3) | 0.58% | — | Pwn.college DojoAI | 29/1/2026 | 17/6/2026 | pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit e33da14449a5abcff507e554f66e2141d6683b0a, missing sandboxing on `/workspace/*` routes allows challenge authors to inject arbitrary javascript which runs on the same origin as `http[:]//dojo[.]website`. This is a sandbox escape… | |
| Aplazada | Crítica (9.5) | 0.47% | — | Pwn.college DojoAI | 14/10/2025 | 17/6/2026 | pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef, the /workspace endpoint contains an improper authentication vulnerability that allows an attacker to access any active Windows VM without proper authorization. The vulnerability occurs in the… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Devdojo VoyagerAILaravelAI | 14/4/2025 | 17/6/2026 | DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command. | |
| Analizada | Alta (8.8) | 0.63% | — | Owasp Defectdojo | 12/8/2024 | 17/6/2026 | An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component. | |
| Modificada | Media (6.1) | 0.39% | — | Dojo WP Affiliate Links | 20/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Internet Marketing Dojo WP Affiliate Links plugin <= 0.1.1 versions. | |
| Modificada | Crítica (9.8) | 30% | — | Linuxfoundation DojoOracle Communications Policy ManagementOracle Primavera UnifierOracle Weblogic Server+1 | 17/12/2021 | 17/6/2026 | All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. | |
| Modificada | Alta (8.6) | 2.0% | — | Linuxfoundation Dojox | 10/3/2020 | 17/6/2026 | In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript… | |
| Modificada | Alta (7.5) | 4.0% | — | Linuxfoundation DojoDebian LinuxOracle Communications Application Session ControllerOracle Communications Policy Management+6 | 10/3/2020 | 17/6/2026 | In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript… | |
| Modificada | Media (6.1) | 1.8% | — | Linuxfoundation DojoxDebian Linux | 13/2/2020 | 17/6/2026 | dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them. | |
| Modificada | Media (6.1) | 1.3% | — | Dojotoolkit Dojo | 6/9/2018 | 17/6/2026 | Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware,… | |
| Modificada | Crítica (9.8) | 2.5% | — | Dojotoolkit DojoDebian Linux | 18/8/2018 | 17/6/2026 | In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid. | |
| Modificada | Media (6.1) | 1.2% | — | Dojotoolkit Dojo | 2/2/2018 | 17/6/2026 | dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element. | |
| Modificada | Media (4.3) | 2.2% | — | Dojotoolkit Dojo | 11/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Dojofoundation Dojo ToolkitIBM Rational Clearquest | 29/12/2010 | 16/6/2026 | Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue. | |
| Modificada | Alta (10) | 3.2% | — | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false options, which makes it easier for remote attackers to have an unspecified impact via a request to a… | |
| Modificada | Media (4.3) | 2.9% | — | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html. | |
| Modificada | Media (4.3) | 1.9% | — | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to… | |
| Modificada | Media (4.3) | 4.5% | — | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to dojo/resources/iframe_history.html,… | |
| Modificada | Alta (10) | 1.3% | — | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors. | |
| Modificada | Alta (7.5) | 1.8% | — | Idojoomla COM Idoblog | 25/9/2009 | 16/6/2026 | SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627. |