Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Ss-proj ShirasagiAI | 10/9/2026 | 10/9/2026 | An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature. | |
| Aplazada | Media (5.1) | 0.24% | — | Ss-proj ShirasagiAI | 10/9/2026 | 10/9/2026 | A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in the web browser of a user who accesses a website using the affected product. | |
| Analizada | Alta (7.5) | 1.0% | — | Ss-proj Shirasagi | 15/10/2024 | 17/6/2026 | SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved when processing crafted HTTP requests. | |
| Modificada | Media (5.3) | 0.71% | — | Ss-proj Shirasagi | 15/9/2023 | 17/6/2026 | SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalization issue. This happens when a logical validation or a security check is performed before a Unicode normalization. The Unicode character equivalent of a character would resurface after the… | |
| Modificada | Media (5.4) | 0.45% | — | Ss-proj Shirasagi | 5/9/2023 | 17/6/2026 | Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product. | |
| Modificada | Media (6.1) | 0.51% | — | Ss-proj Shirasagi | 5/9/2023 | 17/6/2026 | Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product. | |
| Modificada | Alta (8.8) | 1.3% | — | Ss-proj Shirasagi | 5/9/2023 | 17/6/2026 | Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code execution. | |
| Modificada | Media (4.8) | 0.83% | — | Ss-proj Shirasagi | 24/2/2023 | 17/6/2026 | Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script. | |
| Modificada | Media (5.4) | 0.83% | — | Ss-proj Shirasagi | 24/2/2023 | 17/6/2026 | Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script. | |
| Modificada | Media (5.4) | 0.88% | — | Ss-proj Shirasagi | 5/12/2022 | 17/6/2026 | Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. | |
| Modificada | Media (6.1) | 0.98% | — | Ss-proj Shirasagi | 5/12/2022 | 17/6/2026 | Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack. | |
| Modificada | Media (6.1) | 1.0% | — | Ss-proj Shirasagi | 14/6/2022 | 17/6/2026 | Cross-site scripting vulnerability in SHIRASAGI v1.0.0 to v1.14.2, and v1.15.0 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.1) | 1.2% | — | Ss-proj Shirasagi | 10/7/2020 | 17/6/2026 | Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (6.1) | 1.8% | — | Ss-proj Shirasagi | 12/9/2019 | 17/6/2026 | Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. |