Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.94% | — | Mjdm Majordomo | 18/2/2026 | 17/6/2026 | MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() method reads gr('mode') from $_REQUEST and assigns it to $this->mode at the start of execution, making all mode-gated code paths reachable without authentication via the… | |
| Analizada | Crítica (9.3) | 1.1% | — | Mjdm Majordomo | 18/2/2026 | 17/6/2026 | MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning. The saverestore module exposes its admin() method through the /objects/?module=saverestore endpoint without authentication because it uses gr('mode') (which reads… | |
| Analizada | Alta (8.8) | 0.63% | — | Mjdm Majordomo | 18/2/2026 | 17/6/2026 | MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. The commands_search.inc.php file directly interpolates the $_GET['parent'] parameter into multiple SQL queries without sanitization or parameterized queries. The commands module is loadable without… | |
| Analizada | Media (5.3) | 0.40% | — | Mjdm Majordomo | 18/2/2026 | 17/6/2026 | MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability through method parameter injection into the shoutbox. The /objects/?method= endpoint allows unauthenticated execution of stored methods with attacker-controlled parameters. Default methods such as… | |
| Analizada | Media (5.3) | 0.35% | — | Mjdm Majordomo | 18/2/2026 | 17/6/2026 | MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability via the /objects/?op=set endpoint, which is intentionally unauthenticated for IoT device integration. User-supplied property values are stored raw in the database without sanitization. When an administrator views the… | |
| Analizada | Media (5.1) | 0.60% | — | Mjdm Majordomo | 18/2/2026 | 17/6/2026 | MajorDoMo (aka Major Domestic Module) contains a reflected cross-site scripting (XSS) vulnerability in command.php. The $qry parameter is rendered directly into the HTML page without sanitization via htmlspecialchars(), both in an input field value attribute and in a paragraph element. An attacker can inject arbitrary… | |
| Analizada | Crítica (9.2) | 7.0% | — | Mjdm Majordomo | 18/2/2026 | 17/6/2026 | MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is interpolated into a command string within double quotes without sanitization via escapeshellarg(). The command is inserted into a database queue by safe_exec(), which… | |
| Analizada | Crítica (9.3) | 5.1% | — | Mjdm Majordomo | 18/2/2026 | 17/6/2026 | MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.class.php causes execution to continue past a redirect() call that lacks an exit statement, allowing unauthenticated requests to reach the ajax handler in… | |
| Modificada | Crítica (9.8) | 38% | — | Mjdm Majordomo | 15/12/2023 | 17/6/2026 | MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager. | |
| Modificada | Media (5) | 85% | — | MJ2 Majordomo 2 | 15/3/2011 | 16/6/2026 | The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences. NOTE:… | |
| Modificada | Media (5) | 95% | — | MJ2 Majordomo 2 | 4/2/2011 | 16/6/2026 | Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface. | |
| Modificada | Media (4.3) | 0.85% | — | Typo3 Majordomo | 15/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Majordomo extension 1.1.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.6% | — | Great Circle Associates Majordomo | 31/12/2003 | 16/6/2026 | The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command. | |
| Modificada | Media (4.6) | 0.68% | — | Great Circle Associates Majordomo | 28/12/1999 | 16/6/2026 | Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file. | |
| Modificada | Media (4.6) | 0.59% | — | Great Circle Associates Majordomo | 28/12/1999 | 16/6/2026 | resend command in Majordomo allows local users to gain privileges via shell metacharacters. | |
| Modificada | Alta (7.5) | 2.1% | — | Great Circle Associates Majordomo | 24/8/1997 | 16/6/2026 | Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header. | |
| Modificada | Alta (7.5) | 8.7% | — | Great Circle Associates Majordomo | 9/6/1994 | 16/6/2026 | Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command. |