Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.16%—IBM Security Verify Identity Access Reverse ProxyAI15/9/202616/9/2026
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
AplazadaMedia (5.3)0.42%—Reverse ProxyAI23/8/202626/8/2026
Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application percent-decoded, so a %XX sequence in the client URL has become a raw byte by the time the proxy sees it. The proxy appends…
AnalizadaMedia (5.3)0.30%—Reverse Proxy Header Project Reverse Proxy Header30/10/202517/6/2026
Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2.
ModificadaMedia (6.1)1.0%—Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+424/9/202317/6/2026
All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite…
ModificadaMedia (6.1)0.59%—Deothemes AmelaDeothemes ArendelleDeothemes EverseDeothemes Medikaid+118/7/202317/6/2026
Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully…
ModificadaAlta (7.5)2.2%—Microsoft YET Another Reverse Proxy23/6/202317/6/2026
Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability
ModificadaAlta (8.8)0.45%—Jenkins Reverse Proxy Auth16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials.
ModificadaMedia (6.5)0.69%—Jenkins Reverse Proxy Auth15/11/202217/6/2026
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
ModificadaCrítica (9.8)0.97%—Megazone Reversewall-mds17/10/202217/6/2026
Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerability such as stealing account, through remote code execution.
ModificadaCrítica (9.8)1.0%—Generalized Electric Vehicle Reverse Engineering Tool Project Generalized Electric Vehicle Reverse Engineering Tool3/8/202217/6/2026
GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp.
ModificadaAlta (7.5)3.5%—Microsoft YET Another Reverse Proxy15/4/202217/6/2026
YARP Denial of Service Vulnerability
ModificadaCrítica (9.8)1.4%—Pexip InfinityPexip Reverse Proxy AND Turn Server25/9/202017/6/2026
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
ModificadaMedia (6.1)1.0%—Django JS Reverse Project Django JS Reserve23/8/201917/6/2026
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
ModificadaCrítica (9.8)3.2%—Thephpfactory Reverse Auction Factory28/9/201817/6/2026
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
ModificadaBaja (3.3)0.34%—Jenkins Reverse Proxy Auth5/4/201817/6/2026
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.
ModificadaCrítica (9.8)3.8%—Jextn Reverse Auction2/2/201817/6/2026
SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.
ModificadaMedia (5)2.5%—At32 Reverse Proxy8/10/201216/6/2026
at32 Reverse Proxy 1.060.310 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long string in an HTTP header field, as demonstrated using the If-Unmodified-Since field.
ModificadaAlta (10)4.2%—Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+213/7/200516/6/2026
The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the…