Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.1)0.95%—JolokiaAI1/9/20262/9/2026
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and…
Pendiente de análisisAlta (7.5)0.46%—Grafana LokiAI16/7/202616/7/2026
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.
ModificadaAlta (7.7)0.44%—Grafana Loki Datasource22/6/202610/7/2026
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
AnalizadaMedia (5.3)0.41%—Grafana Loki15/4/202617/6/2026
Thanks to Prasanth Sundararajan for reporting this vulnerability.
AplazadaMedia (5.1)0.20%—Zucchetti Axess Cloki Access ControlAI23/12/202517/6/2026
Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users…
AplazadaBaja (2)0.25%—Lokibhardwaj Php-code-for-unlimited-file-uploadAI11/9/202517/6/2026
A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made…
AnalizadaMedia (6.1)0.58%—Neoloki WP Dream Carousel4/2/202517/6/2026
The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (5.3)1.5%—Grafana Loki3/8/202117/6/2026
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of…
ModificadaAlta (8.8)2.7%—JolokiaRedhat Openstack1/8/201917/6/2026
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
ModificadaAlta (8.1)74%—Jolokia Webarchive Agent14/3/201817/6/2026
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
ModificadaMedia (6.1)25%—Jolokia14/3/201817/6/2026
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.
ModificadaMedia (6.8)0.74%—Jolokia6/10/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a crafted web page.
ModificadaMedia (4.3)1.5%—Uloki PHP Forum16/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter.
ModificadaMedia (5)2.4%—Lokicms7/4/200916/6/2026
LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify configuration settings via the LokiACTION parameter in a direct request to admin.php.
ModificadaMedia (5)6.4%—Lokicms26/1/200916/6/2026
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary files via a .. (dot dot) in the page parameter.
ModificadaMedia (5)2.7%—Lokicms4/11/200816/6/2026
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.
ModificadaMedia (6.8)2.4%—Lokicms22/10/200816/6/2026
Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
ModificadaAlta (9.3)3.0%—Lokicms17/4/200816/6/2026
Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.
ModificadaAlta (7.5)1.1%—Loki Download ManagerAI8/6/200516/6/2026
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.