Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.8) | 0.26% | — | PublifyPublify Core | 28/3/2025 | 17/6/2026 | Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions prior to 10.0.2 of the `publify_core` rubygem, publisher on a `publify` application is able to perform a cross-site scripting (XSS) attack on an administrator using the redirect functionality. The… | |
| Modificada | Media (6.5) | 0.70% | — | Publify Project Publify | 29/1/2023 | 17/6/2026 | Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. | |
| Modificada | Crítica (9.8) | 0.91% | — | Publify Project Publify | 14/1/2023 | 17/6/2026 | Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. | |
| Modificada | Media (6.5) | 0.56% | — | Publify Project Publify | 14/1/2023 | 17/6/2026 | Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. | |
| Modificada | Crítica (9.8) | 31% | — | Publify Project Publify | 14/1/2023 | 17/6/2026 | Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. | |
| Modificada | Media (5.4) | 0.75% | — | Publify Project Publify | 23/5/2022 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9. | |
| Modificada | Media (4.3) | 0.83% | — | Publify Project Publify | 23/5/2022 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9. | |
| Modificada | Media (4.9) | 1.2% | — | Publify Project Publify | 16/5/2022 | 17/6/2026 | Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users. | |
| Modificada | Media (6.5) | 0.90% | — | Publify Project Publify | 16/5/2022 | 17/6/2026 | Code Injection in GitHub repository publify/publify prior to 9.2.8. | |
| Modificada | Media (6.5) | 0.83% | — | Publify Project Publify | 16/5/2022 | 17/6/2026 | Improper Access Control in GitHub repository publify/publify prior to 9.2.8. | |
| Modificada | Alta (7.5) | 1.6% | — | Publify Project Publify | 8/2/2022 | 17/6/2026 | Business Logic Errors in GitHub repository publify/publify prior to 9.2.7. | |
| Modificada | Media (5.4) | 0.60% | — | Publify Project Publify | 10/11/2021 | 17/6/2026 | In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. | |
| Modificada | Media (5.4) | 0.60% | — | Publify Project Publify | 10/11/2021 | 17/6/2026 | In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article. | |
| Modificada | Media (6.5) | 0.83% | — | Publify Project Publify | 2/11/2021 | 17/6/2026 | In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only. | |
| Modificada | Alta (7.5) | 1.1% | — | Publify | 9/1/2020 | 17/6/2026 | Publify before 8.0.1 is vulnerable to a Denial of Service attack |