Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.32%—Murasoftware Mura CMS18/3/202617/6/2026
Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
AnalizadaCrítica (9.8)0.26%—Murasoftware Mura CMS18/3/202617/6/2026
Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
AnalizadaAlta (8.1)0.12%—Murasoftware Mura CMS18/3/202617/6/2026
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The vulnerable cTrash.empty function lacks CSRF token validation, enabling malicious websites to forge requests that irreversibly delete all…
AnalizadaAlta (7.1)0.11%—Murasoftware Mura CMS18/3/202617/6/2026
The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function lacks CSRF token validation, enabling malicious websites to forge requests that add, modify, or delete user addresses when an authenticated…
AnalizadaAlta (8.8)0.13%—Murasoftware Mura CMS18/3/202617/6/2026
The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cTrash.restore function lacks CSRF token validation, enabling malicious websites to forge requests that restore content to arbitrary parent…
AnalizadaMedia (6.5)0.16%—Murasoftware Mura CMS18/3/202617/6/2026
MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenticated attackers to force administrators to create and save site bundles containing sensitive data to publicly accessible directories. This vulnerability enables complete…
AnalizadaAlta (8)0.13%—Murasoftware Mura CMS18/3/202617/6/2026
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privileges by adding any user to any group without proper authorization checks. The vulnerable function lacks CSRF token validation and directly…
AnalizadaAlta (8.8)0.16%—Murasoftware Mura CMS18/3/202617/6/2026
The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token validation, enabling malicious websites to forge file upload requests that install attacker-controlled forms…
AplazadaCrítica (9.8)0.41%—Merkur Software B2B Login PanelAI5/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection. This issue affects B2B Login Panel: before 15.01.2025.
ModificadaCrítica (9.8)3.6%—Murasoftware Mura CMS1/2/20239/7/2026
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
ModificadaAlta (7.5)0.95%—Universal-robots UR Software6/4/202017/6/2026
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware and software components (URCaps). These files (*.urcaps) are stored under '/root/.urcaps' as plain…
ModificadaCrítica (9.4)1.5%—Universal-robots UR Software6/4/202017/6/2026
Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starting/stopping programs, shutdown, reset safety and more. The…
ModificadaAlta (8.8)0.59%—Universal-robots UR Software6/4/202017/6/2026
CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Data Exchange) interface on port 30004 which allows setting registers, the speed slider fraction as well as digital and analog Outputs. Additionally unautheticated reading of robot data is also possible
ModificadaMedia (5)2.0%—Pyramid Benhur Software Update31/12/200216/6/2026
The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20.