Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.2%—Indexhibit30/8/202117/6/2026
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
ModificadaMedia (5.4)0.50%—Indexhibit30/8/202117/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
ModificadaMedia (6.1)0.57%—Indexhibit30/8/202117/6/2026
A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
ModificadaMedia (5.7)0.36%—Indexhibit30/8/202117/6/2026
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.
ModificadaMedia (6.5)0.43%—Indexhibit30/8/202117/6/2026
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.
ModificadaAlta (8.8)0.97%—Indexhibit30/8/202117/6/2026
A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
ModificadaCrítica (9.8)39%—Indexhibit14/9/201917/6/2026
Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2.
ModificadaAlta (8.8)2.7%—Indexhibit20/2/201917/6/2026
In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id parameter) in a upd_jxcode=true action to the ndxzstudio/?a=system URI.