Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.22% | — | Dcatadmin Dcat-adminAI | 9/6/2026 | 23/7/2026 | A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting Page. This manipulation of the argument editormd-image-file causes unrestricted upload. The attack can be initiated remotely. The exploit… | |
| Analizada | Crítica (9.8) | 0.46% | — | Dcatadmin Dcat Admin | 2/12/2025 | 17/6/2026 | dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php. | |
| Analizada | Media (5.1) | 0.38% | — | Dcatadmin Dcat Admin | 24/1/2025 | 17/6/2026 | A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown processing of the file /admin/auth/roles of the component Roles Page. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (4.8) | 0.27% | — | Dcatadmin Dcat Admin | 27/12/2024 | 17/6/2026 | Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /admin/auth/extensions. | |
| Analizada | Media (4.8) | 0.32% | — | Dcatadmin Dcat Admin | 27/12/2024 | 17/6/2026 | Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create. | |
| Modificada | Media (6.1) | 0.63% | — | Dcatadmin Dcat Admin | 26/3/2024 | 9/7/2026 | Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box. | |
| Modificada | Media (5.4) | 0.40% | — | Dcatadmin Dcat Admin | 31/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Dcat-Admin v2.1.3-beta allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter. |