Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaNinguna (0)0.44%—Kiwitcms Kiwi TcmsAI17/9/202630/9/2026
Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. The migration command is reentrant, so repeated access reports that no…
AplazadaNinguna (0)0.42%—Kiwitcms Kiwi TcmsAI15/9/202630/9/2026
Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy…
AplazadaMedia (6.1)0.35%—Kiwi TcmsAI15/9/202630/9/2026
Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. The trusted origin can support…
AplazadaAlta (8.8)0.58%—Pikiwidb PikaAI1/9/202624/9/2026
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside…
AnalizadaMedia (5.4)0.31%—Synchroweb Kiwire10/10/202517/6/2026
The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.
AnalizadaAlta (7.3)0.39%—Synchroweb Kiwire10/10/202517/6/2026
The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.
AnalizadaAlta (7.3)0.29%—Synchroweb Kiwire10/10/202517/6/2026
The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database.
AplazadaMedia (6.5)0.21%—Wpkube Kiwi Social ShareAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Kiwi kiwi-social-share allows Stored XSS.This issue affects Kiwi: from n/a through <= 2.1.8.
AnalizadaCrítica (9.3)2.4%—Tikiwiki Cms/groupware15/7/202517/6/2026
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of the web server. The vulnerable component…
AplazadaMedia (6.4)0.30%—Kiwichat NextclientAI2/5/202517/6/2026
The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AnalizadaMedia (4.4)0.38%—Solarwinds Kiwi Cattools17/10/202417/6/2026
SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been enabled for troubleshooting purposes.
ModificadaMedia (5.3)0.41%—Wpkube Kiwi Social Share9/7/202417/6/2026
The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' class. This makes it possible for unauthenticated attackers to view limited content from password protected posts.
ModificadaMedia (5.4)0.69%—Kiwitcms Kiwi Tcms5/7/202317/6/2026
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files as plain text in order to prevent browsers from executing potentially dangerous files when such…
ModificadaCrítica (9.8)1.4%—Wpkube Kiwi Social Share7/6/202317/6/2026
The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitrary…
ModificadaMedia (5.4)0.87%—Kiwitcms Kiwi Tcms6/6/202317/6/2026
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files from being uploaded and…
ModificadaMedia (5.4)0.43%—Kiwitcms Kiwi Tcms27/5/202317/6/2026
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files from being uploaded. The upload…
ModificadaAlta (7.5)0.87%—Kiwiz Invoices Certification & PDF System Project Kiwiz Invoices Certification & PDF System15/5/202317/6/2026
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)
ModificadaAlta (8.8)3.6%—Kiwitcms Kiwi Tcms24/4/202317/6/2026
Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The `github.head_ref` value is an attacker-controlled value.…
AnalizadaCrítica (9)1.0%—Kiwitcms Kiwi Tcms24/4/202317/6/2026
Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior to 12.2, there is no control over what kinds of files can be uploaded. Thus, a malicious actor may upload an `.exe` file or a file containing embedded JavaScript and trick…
ModificadaMedia (4.3)0.42%—Kiwitcms Kiwi Tcms24/4/202317/6/2026
Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account…
ModificadaMedia (5.4)0.48%—Kiwitcms Kiwi Tcms29/3/202317/6/2026
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files uploaded by users which could potentially contain JavaScript code. If SVG images are viewed directly, i.e. not rendered in an HTML page, this JavaScript code could execute. This vulnerability has been…
ModificadaMedia (5.9)0.92%—Kiwitcms Kiwi Tcms15/2/202317/6/2026
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-service attacks against the Password reset page. An attacker could potentially send a large number of emails if they know the email addresses of users in Kiwi TCMS.…
ModificadaCrítica (9.8)0.91%—Kiwitcms Kiwi Tcms15/2/202317/6/2026
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch. As a workaround, users may install and configure a rate-limiting proxy in front…
ModificadaAlta (8.8)0.68%—Kiwitcms Kiwi Tcms2/1/202317/6/2026
Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to guess password. This issue is resolved by providing defaults for the `AUTH_PASSWORD_VALIDATORS`…
ModificadaMedia (5.4)0.49%—Kiwitcms Kiwi Tcms21/11/202217/6/2026
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.