Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.3% | — | Nextcloud Cookbook | 26/5/2023 | 17/6/2026 | NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `main-0.9.x` branch, the `pull-checks.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The `github.head_ref` value is an… | |
| Modificada | Alta (7.8) | 0.51% | — | Jgit-cookbook Project Jgit-cookbook | 28/12/2022 | 17/6/2026 | A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to insecure temporary file. The attack can be initiated remotely. The name of the patch is b8cb29b43dc704708d598c60ac1881db7cf8e9c3. It is recommended to apply a… | |
| Modificada | Alta (7.8) | 0.27% | — | SAP Business-one-hana-chef-cookbookSAP Business ONE | 11/5/2021 | 17/6/2026 | Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure… | |
| Modificada | Alta (7.1) | 0.26% | — | SAP Business-one-hana-chef-cookbookSAP Business ONE | 11/5/2021 | 17/6/2026 | SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby highly impacting the integrity and… | |
| Modificada | Alta (7.8) | 0.26% | — | SAP Chef Business-one-cookbook | 11/5/2021 | 17/6/2026 | Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to access information which would otherwise be restricted, which could lead to Information Disclosure… | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Joomla COM Pccookbook | 29/1/2009 | 16/6/2026 | SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php, a different vector than CVE-2008-0844. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Joomla COM GaryscookbookMambo COM Garyscookbook | 4/3/2008 | 16/6/2026 | SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Joomla COM Pccookbook | 20/2/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | |
| Modificada | Media (6.8) | 6.2% | 💥 Exploit | Joomla PC Cookbook | 12/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter. |