Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.2% | — | Indexhibit | 30/8/2021 | 17/6/2026 | An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files. | |
| Modificada | Media (5.4) | 0.50% | — | Indexhibit | 30/8/2021 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (6.1) | 0.57% | — | Indexhibit | 30/8/2021 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (5.7) | 0.36% | — | Indexhibit | 30/8/2021 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords. | |
| Modificada | Media (6.5) | 0.43% | — | Indexhibit | 30/8/2021 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts. | |
| Modificada | Alta (8.8) | 0.97% | — | Indexhibit | 30/8/2021 | 17/6/2026 | A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell. | |
| Modificada | Crítica (9.8) | 39% | — | Indexhibit | 14/9/2019 | 17/6/2026 | Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2. | |
| Modificada | Alta (8.8) | 2.7% | — | Indexhibit | 20/2/2019 | 17/6/2026 | In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id parameter) in a upd_jxcode=true action to the ndxzstudio/?a=system URI. |