Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.55%—EtherpadAI19/8/20269/9/2026
Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute escaping. A pad editor can place an attacker-controlled value into the attribute pool…
AplazadaCrítica (9.9)0.46%—EtherpadAI19/8/20269/9/2026
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists, while src/node/security/OAuth2Provider.ts…
AplazadaMedia (6.8)0.44%—EtherpadAI19/8/20269/9/2026
Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTransfer/{uuid}. Although the record includes createdAt, the transfer has no…
AplazadaMedia (6.1)0.58%—EtherpadAI19/8/20269/9/2026
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admin without sanitization, Vary: x-proxy-path, or Cache-Control: private, no-store. A…
AplazadaMedia (4.2)0.14%—EtherpadAI19/8/20269/9/2026
Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared world-writable temporary directory, a local unprivileged attacker who predicts a…
AplazadaCrítica (9.6)0.47%—EtherpadAI19/8/20269/9/2026
Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the generated markup to node.innerHTML. ImportEtherpad.setPadRaw in…
ModificadaAlta (8.8)2.1%—Etherpad9/12/202117/6/2026
Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the attacker to gain admin privileges for the Etherpad instance. This, in turn, can be used to install a malicious Etherpad plugin that can execute arbitrary code…
ModificadaAlta (7.2)2.2%—Etherpad21/7/202117/6/2026
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.
ModificadaMedia (6.1)1.3%—Etherpad19/7/202117/6/2026
A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML by importing a crafted pad.
ModificadaAlta (7.5)1.1%—Etherpad28/4/202117/6/2026
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.
ModificadaAlta (7.5)1.0%—Etherpad Ueberdb28/4/202117/6/2026
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
ModificadaMedia (6.5)0.64%—Etherpad28/4/202117/6/2026
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.
ModificadaAlta (7.5)1.1%—Etherpad28/4/202117/6/2026
Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instance.
ModificadaAlta (7.5)1.1%—Etherpad28/4/202117/6/2026
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance).
ModificadaAlta (7.5)2.3%—Etherpad13/2/202017/6/2026
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE: This vulnerability is due to an incomplete fix to CVE-2015-3297.
ModificadaMedia (6.1)0.68%—Etherpad19/10/201917/6/2026
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
ModificadaCrítica (9.8)13%—Etherpad Lite29/4/201817/6/2026
Etherpad Lite before 1.6.4 is exploitable for admin access.
ModificadaAlta (8.1)1.6%—Etherpad7/4/201817/6/2026
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).
ModificadaCrítica (9.8)2.0%—Etherpad7/4/201817/6/2026
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.
ModificadaAlta (7.5)1.2%—Etherpad7/4/201817/6/2026
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
ModificadaCrítica (9.8)2.3%—Etherpad8/2/201817/6/2026
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
ModificadaMedia (6.1)0.88%—Etherpad Lite8/2/201817/6/2026
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
ModificadaAlta (7.5)2.3%—Etherpad12/1/201817/6/2026
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.
ModificadaAlta (7.5)2.3%—Etherpad7/9/201717/6/2026
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
ModificadaAlta (7.5)5.0%—Etherpad7/7/201717/6/2026
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests.