Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.44%—OcomonAI13/8/202417/6/2026
A vulnerability, which was classified as problematic, has been found in OcoMon 4.0RC1/4.0/5.0RC1. This issue affects some unknown processing of the file /includes/common/require_access_recovery.php of the component URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The…
ModificadaAlta (8.8)0.68%—Ocomon Project Ocomon26/10/202317/6/2026
A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file.
ModificadaAlta (7.5)0.53%—Ocomon Project Ocomon26/10/202317/6/2026
An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obtain sensitive information such as e-mails and usernames.
ModificadaAlta (7.5)0.87%—Ocomon Project Ocomon19/10/202217/6/2026
OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover.
ModificadaCrítica (9.8)0.81%—Ocomon Project Ocomon13/10/202217/6/2026
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
ModificadaCrítica (9.8)0.81%—Ocomon Project Ocomon13/10/202217/6/2026
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.
ModificadaMedia (5)1.3%—Ocomon31/12/200516/6/2026
Multiple SQL injection vulnerabilities in OcoMon 1.20, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form, a different vulnerability than CVE-2005-4664.
ModificadaMedia (5)1.1%—Ocomon31/12/200516/6/2026
SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.
ModificadaMedia (4.3)1.2%—Ocomon31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.