Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.95% | — | JolokiaAI | 1/9/2026 | 2/9/2026 | A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Grafana LokiAI | 16/7/2026 | 16/7/2026 | Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. | |
| Modificada | Alta (7.7) | 0.44% | — | Grafana Loki Datasource | 22/6/2026 | 10/7/2026 | A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information. | |
| Analizada | Media (5.3) | 0.41% | — | Grafana Loki | 15/4/2026 | 17/6/2026 | Thanks to Prasanth Sundararajan for reporting this vulnerability. | |
| Aplazada | Media (5.1) | 0.20% | — | Zucchetti Axess Cloki Access ControlAI | 23/12/2025 | 17/6/2026 | Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users… | |
| Aplazada | Baja (2) | 0.25% | — | Lokibhardwaj Php-code-for-unlimited-file-uploadAI | 11/9/2025 | 17/6/2026 | A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made… | |
| Analizada | Media (6.1) | 0.58% | — | Neoloki WP Dream Carousel | 4/2/2025 | 17/6/2026 | The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.3) | 1.5% | — | Grafana Loki | 3/8/2021 | 17/6/2026 | An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of… | |
| Modificada | Alta (8.8) | 2.7% | — | JolokiaRedhat Openstack | 1/8/2019 | 17/6/2026 | A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack. | |
| Modificada | Alta (8.1) | 74% | — | Jolokia Webarchive Agent | 14/3/2018 | 17/6/2026 | A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server. | |
| Modificada | Media (6.1) | 25% | — | Jolokia | 14/3/2018 | 17/6/2026 | An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser. | |
| Modificada | Media (6.8) | 0.74% | — | Jolokia | 6/10/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a crafted web page. | |
| Modificada | Media (4.3) | 1.5% | — | Uloki PHP Forum | 16/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter. | |
| Modificada | Media (5) | 2.4% | — | Lokicms | 7/4/2009 | 16/6/2026 | LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify configuration settings via the LokiACTION parameter in a direct request to admin.php. | |
| Modificada | Media (5) | 6.4% | — | Lokicms | 26/1/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary files via a .. (dot dot) in the page parameter. | |
| Modificada | Media (5) | 2.7% | — | Lokicms | 4/11/2008 | 16/6/2026 | Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter. | |
| Modificada | Media (6.8) | 2.4% | — | Lokicms | 22/10/2008 | 16/6/2026 | Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter. | |
| Modificada | Alta (9.3) | 3.0% | — | Lokicms | 17/4/2008 | 16/6/2026 | Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Loki Download ManagerAI | 8/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp. |