Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.34%—Exceedone Exment18/10/202417/6/2026
Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When accessing the edit screen containing custom columns (column type: images or files), an arbitrary script may be executed on the web browser of the user.
AnalizadaBaja (3.8)0.37%—Exceedone Exment18/10/202417/6/2026
Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. A logged-in user with the permission of table management may obtain and/or alter the information of the unauthorized table.
AnalizadaMedia (6.1)0.37%—Opentext Exceed Turbox13/3/202417/6/2026
HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site scripting.
AnalizadaCrítica (9.8)0.27%—Opentext Exceed Turbox13/3/202417/6/2026
Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.
AnalizadaAlta (7.5)0.50%—Opentext Exceed Turbox13/3/202417/6/2026
Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC.
ModificadaMedia (5.4)0.91%—Exceedone ExmentExceedone Laravel-admin24/8/202217/6/2026
Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.
ModificadaMedia (5.4)0.91%—Exceedone ExmentExceedone Laravel-admin24/8/202217/6/2026
Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.
ModificadaAlta (8.8)1.4%—Exceedone ExmentExceedone Laravel-admin24/8/202217/6/2026
SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.
ModificadaMedia (5.4)0.64%—Exceedone Exment25/8/202017/6/2026
Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via a specially crafted file.
ModificadaMedia (5.4)0.66%—Exceedone Exment25/8/202017/6/2026
Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via unspecified vectors.
ModificadaMedia (6.4)1.2%—Opentext Exceed Ondemand19/5/201417/6/2026
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.
ModificadaMedia (6.8)0.63%—Opentext Exceed Ondemand19/5/201417/6/2026
The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.
ModificadaMedia (6.8)1.0%—Opentext Exceed Ondemand19/5/201417/6/2026
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.
ModificadaMedia (5)0.71%—Opentext Exceed Ondemand19/5/201417/6/2026
OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a .eod8 file.
ModificadaMedia (6.8)6.9%—Hummingbird ExceedHummingbird Exceed Powersuite24/10/200816/6/2026
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. NOTE: code execution might not be possible in 13.0.
ModificadaBaja (2.1)0.33%—Hummingbird Exceed31/12/200416/6/2026
Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab.
ModificadaMedia (5)1.3%—Hummingbird Exceed7/4/199916/6/2026
Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.
ModificadaAlta (7.5)1.1%—Hummingbird Exceed3/12/199816/6/2026
Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.