Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.44% | — | OcomonAI | 13/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in OcoMon 4.0RC1/4.0/5.0RC1. This issue affects some unknown processing of the file /includes/common/require_access_recovery.php of the component URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The… | |
| Modificada | Alta (8.8) | 0.68% | — | Ocomon Project Ocomon | 26/10/2023 | 17/6/2026 | A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file. | |
| Modificada | Alta (7.5) | 0.53% | — | Ocomon Project Ocomon | 26/10/2023 | 17/6/2026 | An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obtain sensitive information such as e-mails and usernames. | |
| Modificada | Alta (7.5) | 0.87% | — | Ocomon Project Ocomon | 19/10/2022 | 17/6/2026 | OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover. | |
| Modificada | Crítica (9.8) | 0.81% | — | Ocomon Project Ocomon | 13/10/2022 | 17/6/2026 | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. | |
| Modificada | Crítica (9.8) | 0.81% | — | Ocomon Project Ocomon | 13/10/2022 | 17/6/2026 | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php. | |
| Modificada | Media (5) | 1.3% | — | Ocomon | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in OcoMon 1.20, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form, a different vulnerability than CVE-2005-4664. | |
| Modificada | Media (5) | 1.1% | — | Ocomon | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662. | |
| Modificada | Media (4.3) | 1.2% | — | Ocomon | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. |