Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

34 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.37%—TestlinkAI7/8/202624/9/2026
TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the attachmentdownload.php handler without any project or role authorization check.…
AnalizadaAlta (8.1)0.43%—Testlink27/9/202417/6/2026
TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's…
AnalizadaMedia (6.1)0.35%—Testlink26/8/202417/6/2026
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.
ModificadaAlta (7.5)0.65%—Testlink30/12/202317/6/2026
TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.
ModificadaAlta (8.8)0.50%—Testlink20/9/202217/6/2026
TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.
ModificadaMedia (5.4)0.65%—Testlink16/9/202217/6/2026
TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.
ModificadaAlta (7.2)1.3%—Testlink16/9/202217/6/2026
TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php
ModificadaAlta (7.2)1.2%—Testlink16/9/202217/6/2026
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
ModificadaCrítica (9.8)1.2%—Testlink27/4/202017/6/2026
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.
ModificadaAlta (7.5)0.75%—Testlink27/4/202017/6/2026
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
ModificadaAlta (8.8)16%—Testlink3/4/202017/6/2026
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a…
ModificadaCrítica (9.8)1.7%—Testlink3/4/202017/6/2026
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.
ModificadaCrítica (9.8)2.9%—Testlink3/4/202017/6/2026
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
ModificadaAlta (8.8)2.0%—Testlink5/3/202017/6/2026
Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id parameter to reqCompareVersions.php; the (4)…
ModificadaAlta (8.8)1.4%—Testlink10/2/202017/6/2026
An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.
ModificadaMedia (6.1)0.95%—Testlink20/1/202017/6/2026
TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists because of an incomplete fix for CVE-2019-19491.
ModificadaMedia (6.1)0.79%—Testlink2/12/201917/6/2026
TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request.
ModificadaMedia (5.3)0.50%—Jenkins Testlink7/8/201917/6/2026
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaMedia (6.1)0.91%—Testlink1/8/201917/6/2026
TestLink 1.9.19 has XSS via the error.php message parameter.
ModificadaMedia (5.4)0.70%—Jenkins Testlink13/3/201817/6/2026
A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript
ModificadaAlta (7.5)1.5%—Testlink5/3/201817/6/2026
TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.
ModificadaAlta (7.5)6.1%—Testlink25/2/201817/6/2026
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value.
ModificadaMedia (6.1)0.76%—Testlink26/9/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date parameter to lib/results/tcCreatedPerUserOnTestProject.php; the (3) containerType parameter to…
ModificadaCrítica (9.8)1.6%—Testlink26/9/201717/6/2026
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.
ModificadaMedia (5)2.6%—Testlink31/10/201417/6/2026
lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified vectors, which reveals the installation path in an error message.