Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.24% | — | Lucapaggetti 3D Presentation | 10/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lpagg 3D Presentation 3d-presentation allows Stored XSS.This issue affects 3D Presentation: from n/a through <= 1.0. | |
| Analizada | Alta (8.8) | 0.98% | — | Ferrislucas Promptr | 25/9/2024 | 17/6/2026 | A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL. | |
| Analizada | Media (6.5) | 0.19% | — | Lucasgarcia Posts Reminder | 17/9/2024 | 17/6/2026 | The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Media (6.1) | 0.33% | — | Lucasstad Lucas String Replace | 13/9/2024 | 17/6/2026 | The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Analizada | Crítica (9.8) | 2.9% | — | 89luca89 Distrobox | 21/3/2024 | 17/6/2026 | Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables. | |
| Modificada | Media (6.1) | 0.49% | — | Evolucare ECS Imaging | 22/3/2023 | 17/6/2026 | EVOLUCARE ECSIMAGING (aka ECS Imaging) < 6.21.5 is vulnerable to Cross Site Scripting (XSS) via new_movie. php. | |
| Modificada | Alta (7.5) | 0.90% | — | Luca-app Luca | 4/6/2021 | 17/6/2026 | The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digital signature. | |
| Modificada | Alta (7.5) | 2.8% | — | Luca-app Luca | 4/6/2021 | 17/6/2026 | Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting. | |
| Modificada | Alta (7.5) | 2.8% | — | Luca-app Luca | 4/6/2021 | 17/6/2026 | Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after requests for Phone Number Registration. | |
| Modificada | Crítica (9.8) | 3.1% | — | Evolucare ECS Imaging | 7/1/2021 | 17/6/2026 | EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The parameter "file" on the webpage /showfile.php can be exploited to gain root access. NOTE: This vulnerability only affects products that are no longer supported by the… | |
| Modificada | Alta (7.5) | 1.1% | — | Oracle Micros Lucas | 23/4/2019 | 17/6/2026 | Vulnerability in the MICROS Lucas component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 2.9.5.6 and 2.9.5.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise MICROS Lucas. Successful attacks of this… | |
| Modificada | Alta (7.5) | 3.2% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Network Integrity+24 | 25/6/2018 | 17/6/2026 | Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not… | |
| Modificada | Media (5.9) | 2.7% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Diameter Signaling Router+29 | 25/6/2018 | 25/8/2026 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a… | |
| Modificada | Alta (8.8) | 2.5% | — | Pivotal Software Spring SecurityVmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+38 | 11/5/2018 | 25/8/2026 | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Modificada | Media (5) | 1.8% | — | Lucas Clemente Vella Libpam-pgsql | 3/6/2014 | 16/6/2026 | libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass authentication via a crafted password. | |
| Modificada | Media (4.3) | 1.0% | — | Luca Corbo Ortro | 19/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Ortro before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.3% | — | Matteo Lucarelli 3editor CMS | 31/12/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Matteolucarelli Pgmreloaded | 23/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to (a) index.php, the (2) CFG[libdir] and (3) CFG[localedir] parameters to (b) common.inc.php, and the CFG[localelangdir] parameter to (c)… | |
| Modificada | Alta (7.5) | 1.2% | — | Lucas Rodriguez SAN Pedro YET Another News System | 15/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in the login_user function in yans.func.php in Lucas Rodriguez San Pedro Yet Another News System (YANS) 0.2b allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Gianluca Baldo PhpauctionPhpadsnew | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path parameter. | |
| Modificada | Media (4.6) | 0.87% | — | Luca Deri Ntop | 1/11/2005 | 16/6/2026 | The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.4% | — | Gianluca Baldo Phpauction | 13/7/2005 | 16/6/2026 | PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID. | |
| Modificada | Media (4.3) | 0.99% | — | Gianluca Baldo Phpauction | 13/7/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php. NOTE: there is evidence that viewnews.php and login.php may not be part of… | |
| Modificada | Alta (7.5) | 1.2% | — | Gianluca Baldo Phpauction | 13/7/2005 | 16/6/2026 | SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this description. |