Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

81 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.41%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.
AplazadaAlta (8.9)0.43%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict MIME verification and GD binary raster…
AplazadaAlta (8.6)0.42%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escaping, allowing injection of malicious…
AplazadaMedia (5.1)0.39%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or core.admin). An authenticated user could submit…
AplazadaMedia (5.1)0.39%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image path (src) belonged to that article. On…
ModificadaAlta (8.8)0.50%—Ollyo Helix Ultimate13/7/202623/7/2026
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
ModificadaAlta (8.7)0.25%—Ollyo Helix Ultimate13/7/202623/7/2026
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
AnalizadaAlta (7.5)0.35%—Apache Helix9/7/20269/7/2026
Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to…
AnalizadaAlta (7.5)0.99%—Ollyo Helix329/6/202630/6/2026
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
Pendiente de análisisAlta (7.7)0.70%—Perforce Helix CoreAI18/5/202617/6/2026
A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.
AplazadaMedia (6.3)0.46%—Perforce Helix ALMAI15/4/202517/6/2026
Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.
AplazadaAlta (8.7)0.49%—Perforce Helix CoreAI11/11/202417/6/2026
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.
AplazadaAlta (8.7)0.49%—Perforce Helix CoreAI11/11/202417/6/2026
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek.
AplazadaAlta (8.7)0.49%—Perforce Helix CoreAI11/11/202417/6/2026
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek.
AplazadaMedia (5.8)0.20%—Perforce Helix CoreAI25/9/202417/6/2026
In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified.
AnalizadaAlta (7.5)0.73%—Apache Helix20/8/202417/6/2026
** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is retired, we do not plan to release a version that fixes this…
AplazadaBaja (2)0.61%—Helix ALMAI28/6/202417/6/2026
In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.
ModificadaAlta (7.8)0.75%—Perforce Helix Sync1/2/202417/6/2026
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.
ModificadaAlta (7.5)0.95%—Perforce Helix Core8/11/202317/6/2026
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.
ModificadaCrítica (9.8)1.1%—Perforce Helix Core8/11/202317/6/2026
An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.
ModificadaAlta (7.5)0.95%—Perforce Helix Core8/11/202317/6/2026
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner.
ModificadaAlta (7.5)0.95%—Perforce Helix Core8/11/202317/6/2026
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.
ModificadaCrítica (9.8)2.0%—Apache Helix26/7/202317/6/2026
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code execution. The code can be run in Helix REST start…
ModificadaMedia (6.1)1.1%—Apache Helix19/12/202217/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper designed for UI embedding. User please upgrade to 1.1.0 to fix…
ModificadaMedia (6.7)0.27%—Lenovo Thinkpad 11E FirmwareLenovo Thinkpad Helix FirmwareLenovo Thinkpad L560 FirmwareLenovo Thinkpad L570 Firmware+2622/4/202217/6/2026
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.