Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.8)0.26%—PublifyPublify Core28/3/202517/6/2026
Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions prior to 10.0.2 of the `publify_core` rubygem, publisher on a `publify` application is able to perform a cross-site scripting (XSS) attack on an administrator using the redirect functionality. The…
ModificadaMedia (6.5)0.70%—Publify Project Publify29/1/202317/6/2026
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.
ModificadaCrítica (9.8)0.91%—Publify Project Publify14/1/202317/6/2026
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.
ModificadaMedia (6.5)0.56%—Publify Project Publify14/1/202317/6/2026
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.
ModificadaCrítica (9.8)31%—Publify Project Publify14/1/202317/6/2026
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.
ModificadaMedia (5.4)0.75%—Publify Project Publify23/5/202217/6/2026
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.
ModificadaMedia (4.3)0.83%—Publify Project Publify23/5/202217/6/2026
Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.
ModificadaMedia (4.9)1.2%—Publify Project Publify16/5/202217/6/2026
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.
ModificadaMedia (6.5)0.90%—Publify Project Publify16/5/202217/6/2026
Code Injection in GitHub repository publify/publify prior to 9.2.8.
ModificadaMedia (6.5)0.83%—Publify Project Publify16/5/202217/6/2026
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
ModificadaAlta (7.5)1.6%—Publify Project Publify8/2/202217/6/2026
Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.
ModificadaMedia (5.4)0.60%—Publify Project Publify10/11/202117/6/2026
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.
ModificadaMedia (5.4)0.60%—Publify Project Publify10/11/202117/6/2026
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.
ModificadaMedia (6.5)0.83%—Publify Project Publify2/11/202117/6/2026
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.
ModificadaAlta (7.5)1.1%—Publify9/1/202017/6/2026
Publify before 8.0.1 is vulnerable to a Denial of Service attack