Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.4% | — | Telaxius Epesi | 22/9/2017 | 17/6/2026 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter. | |
| Modificada | Media (5.4) | 0.64% | — | Telaxius Epesi | 22/9/2017 | 17/6/2026 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter. | |
| Modificada | Media (5.4) | 0.64% | — | Telaxius Epesi | 22/9/2017 | 17/6/2026 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter. | |
| Modificada | Media (5.4) | 0.63% | — | Telaxius Epesi | 22/9/2017 | 17/6/2026 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter. | |
| Modificada | Media (5.4) | 0.63% | — | Telaxius Epesi | 22/9/2017 | 17/6/2026 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter. | |
| Modificada | Media (5.4) | 1.4% | — | Telaxius Epesi | 22/9/2017 | 17/6/2026 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Epesi | 14/6/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted currency decimal-sign data. | |
| Modificada | Media (6.1) | 1.0% | — | Epesi | 14/6/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted country data. | |
| Modificada | Media (6.1) | 1.0% | — | Epesi | 14/6/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted common data. | |
| Modificada | Media (6.1) | 1.0% | — | Epesi | 14/6/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in modules/Base/Lang/Administrator/update_translation.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) original or (2) new parameter. | |
| Modificada | Media (4.8) | 0.67% | — | Epesi | 2/6/2017 | 17/6/2026 | Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted tab_name parameter. | |
| Modificada | Media (5.4) | 0.66% | — | Epesi | 1/6/2017 | 17/6/2026 | The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted meeting description parameter. | |
| Modificada | Media (6.1) | 0.77% | — | Telaxius Epesi | 4/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lacks the cid parameter. | |
| Modificada | Media (6.1) | 0.78% | — | Epesi | 5/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (tooltip_id, callback, args, cid) passed to the EPESI-master/modules/Utils/Tooltip/req.php URL. An attacker could execute arbitrary HTML and script code in a… | |
| Modificada | Media (6.1) | 0.78% | — | Epesi | 5/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (cid, value, element, mode, tab, form_name, id) passed to the EPESI-master/modules/Utils/RecordBrowser/grid.php URL. An attacker could execute arbitrary HTML and… | |
| Modificada | Media (6.1) | 0.78% | — | Epesi | 5/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (element, state, cat, id, cid) passed to the EPESI-master/modules/Utils/Watchdog/subscribe.php URL. An attacker could execute arbitrary HTML and script code in a… | |
| Modificada | Media (6.1) | 0.78% | — | Epesi | 5/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (visible, tab, cid) passed to the EPESI-master/modules/Utils/RecordBrowser/Filters/save_filters.php URL. An attacker could execute arbitrary HTML and script code… | |
| Modificada | Media (6.1) | 0.78% | — | Epesi | 5/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (state, element, id, tab, cid) passed to the "EPESI-master/modules/Utils/RecordBrowser/favorites.php" URL. An attacker could execute arbitrary HTML and script code… | |
| Modificada | Media (6.8) | 1.2% | — | Telaxus LLC Epesi | 26/7/2007 | 16/6/2026 | epesi framework before 0.8.6 does not properly verify file extensions, which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images upload feature. NOTE: some of these details are obtained from third party information. |