Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Accellion File Transfer Appliance29/4/202017/6/2026
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').
ModificadaCrítica (9.8)1.1%—Accellion File Transfer Appliance29/4/202017/6/2026
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.
ModificadaAlta (7.5)57%—Accellion File Transfer Appliance10/10/201717/6/2026
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. (dot dot) in the statecode cookie.
ModificadaCrítica (9.8)84%—Accellion File Transfer Appliance22/8/201717/6/2026
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.
ModificadaCrítica (9.8)1.2%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.
ModificadaCrítica (10)1.9%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
ModificadaAlta (8.8)0.51%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass…
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos/courier/login.html auth_params CRLF attack vector.
ModificadaCrítica (9.8)1.4%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
ModificadaCrítica (9.8)1.2%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF vulnerability in settings_global_text_edit.php allowing ?display=x%0Dnewline attacks.
ModificadaMedia (6.1)1.2%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL…
ModificadaMedia (6.1)0.68%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.
ModificadaCrítica (9.8)24%—Accellion File Transfer Appliance5/5/201717/6/2026
An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.
ModificadaAlta (7.8)0.47%—Accellion File Transfer Appliance7/5/201617/6/2026
The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows local users to add an SSH key to an arbitrary group, and consequently gain privileges, via unspecified vectors.
ModificadaAlta (8.8)5.4%—Accellion File Transfer Appliance7/5/201617/6/2026
The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote authenticated users to execute arbitrary commands by leveraging the YUM_CLIENT restricted-user role.
ModificadaCrítica (9.8)1.6%—Accellion File Transfer Appliance7/5/201617/6/2026
SQL injection vulnerability in home/seos/courier/security_key2.api on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote attackers to execute arbitrary SQL commands via the client_id parameter.
ModificadaMedia (6.1)0.94%—Accellion File Transfer Appliance7/5/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) getimageajax.php, (2) move_partition_frame.html, or (3) wmInfo.html.
ModificadaAlta (7.2)0.82%—Accellion Secure File Transfer Appliance19/2/201016/6/2026
Accellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the --file_move action in /usr/local/bin/admin.pl, or a hard link attack…
ModificadaMedia (4.3)1.1%—Accellion Secure File Transfer Appliance19/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit logs.
ModificadaAlta (9)1.7%—Accellion Secure File Transfer Appliance19/2/201016/6/2026
Static code injection vulnerability in the administrative web interface in Accellion Secure File Transfer Appliance allows remote authenticated administrators to inject arbitrary shell commands by appending them to a request to update the SNMP public community string.
ModificadaAlta (7.8)2.8%—Accellion Secure File Transfer Appliance19/2/201016/6/2026
Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
ModificadaAlta (9)2.4%—Accellion Secure File Transfer Appliance19/2/201016/6/2026
Accellion Secure File Transfer Appliance before 8_0_105 allows remote authenticated administrators to bypass the restricted shell and execute arbitrary commands via shell metacharacters to the ping command, as demonstrated by modifying the cli program.