Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.30% | — | Silverstripe ElementalAI | 10/4/2025 | 17/6/2026 | Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page out of rather than a single text field. An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that… | |
| Modificada | Alta (7.5) | 0.90% | — | Elementalx | 1/1/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in flar2 ElementalX up to 6.x on Nexus 9. Affected is the function xfrm_dump_policy_done of the file net/xfrm/xfrm_user.c of the component ipsec. The manipulation leads to denial of service. Upgrading to version 7.00 is able to address this issue. The name of… | |
| Modificada | Media (5.4) | 0.44% | — | Elementalpath Cognitoys Dino Firmware | 8/8/2019 | 17/6/2026 | Cognitoys Dino devices allow profiles_add.html CSRF. | |
| Modificada | Media (6.1) | 0.83% | — | Elementalpath Cognitoys Dino Firmware | 8/8/2019 | 17/6/2026 | Cognitoys Dino devices allow XSS via the SSID. | |
| Modificada | Media (4.3) | 1.2% | — | Elemental Software Cartwiz | 3/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Elemental Software Cartwiz | 27/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Elemental Software Cartwiz | 11/7/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp. | |
| Modificada | Media (4.3) | 0.99% | — | Elemental Software Cartwiz | 11/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Elemental Software Cartwiz | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp,… |