Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 300 respecto a la semana anterior
Críticas / altas1348▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.35%—Typo3AIStanislas Rolland SR Feuser RegisterAI21/5/202517/6/2026
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
AplazadaCrítica (10)0.71%—Stanislas Rolland SR Feuser RegisterAI21/5/202517/6/2026
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.
ModificadaMedia (5)1.4%—Stanislas Rolland SR Feuser Register17/11/201216/6/2026
The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via the (1) edit perspective or (2) autologin feature.
ModificadaMedia (4)1.2%—Stanislas Rolland SR Feuser Register7/4/200916/6/2026
Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.
ModificadaMedia (4.3)1.0%—Typo3 SR Feuser Register Extension16/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in the sr_feuser_register 1.4.0, 1.6.0, 2.2.1 to 2.2.7, 2.3.0 to 2.3.6, 2.4.0, and 2.5.0 to 2.5.9 extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.6%—Typo3 SR Feuser Register Extension16/5/200816/6/2026
Unspecified vulnerability in sr_feuser_register 1.4.0, 1.6.0, 2.2.1 to 2.2.7, 2.3.0 to 2.3.6, 2.4.0, and 2.5.0 to 2.5.9 extension for TYPO3 allows remote attackers to execute arbitrary code and delete arbitrary files via unspecified attack vectors.