Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.72%—Digitialpixies Oauth ClientAI16/8/202626/8/2026
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no…
AplazadaCrítica (9.8)0.61%—Digitialpixies Oauth ClientAI13/8/202614/8/2026
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
ModificadaMedia (6.5)0.36%—Digitialpixies Oauth Client14/11/202217/6/2026
The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions.
ModificadaMedia (4.8)0.53%—Digitialpixies Oauth Client14/11/202217/6/2026
The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
ModificadaCrítica (9.8)1.5%—Pixie Project Pixie19/11/201917/6/2026
Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
ModificadaCrítica (10)2.6%—Vebto Pixie - Image Editor25/9/201717/6/2026
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.
ModificadaCrítica (9.8)5.0%—Lucidcrew Pixie3/4/201717/6/2026
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.
ModificadaMedia (6.1)0.80%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.
ModificadaMedia (6.1)0.82%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
ModificadaMedia (6.1)0.82%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
ModificadaMedia (6.1)0.80%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
ModificadaMedia (6.1)1.2%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
ModificadaMedia (4.3)1.4%—Lucidcrew Pixie4/6/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/.
ModificadaAlta (7.5)1.7%—Getpixie PixieLucidcrew Pixie8/12/201116/6/2026
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.
ModificadaMedia (5)1.9%—Lucidcrew Pixie24/9/201116/6/2026
Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files.
ModificadaMedia (4.3)3.7%—Getpixie Pixie CMS26/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter.
ModificadaAlta (7.5)2.4%—Getpixie Pixie CMS26/3/200916/6/2026
SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header in a request.
ModificadaAlta (7.5)1.1%—Getpixie Pixie CMS26/3/200916/6/2026
SQL injection vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the x parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.