Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 93 respecto a la semana anterior
Críticas / altas1464▲ 354 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 418 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.62% | — | Element-it Http Commander | 3/3/2022 | 9/7/2026 | A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field. | |
| Modificada | Media (5.4) | 0.74% | — | Element-it Http Commander | 13/1/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote authenticated users to inject arbitrary web script or HTML via filenames. | |
| Modificada | Media (6.5) | 1.3% | — | Element-it Http Commander | 14/7/2021 | 17/6/2026 | An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP files from the internal server network by inserting an internal address. | |
| Modificada | Media (5.4) | 0.74% | — | Element-it Http Commander | 14/7/2021 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SVG image. | |
| Modificada | Media (6.5) | 1.7% | — | Element-it Http Commander | 14/7/2021 | 17/6/2026 | A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to write files to arbitrary directories via relative paths in ZIP archives. | |
| Modificada | Media (4.3) | 1.7% | — | Http Commander | 30/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander 6.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) LogoffMessage parameter to logofflast.aspx or the (2) txtUsername parameter to Default.aspx. NOTE: The provenance of this information is unknown;… | |
| Modificada | Media (5) | 1.9% | — | Http CommanderAI | 31/12/2003 | 16/6/2026 | HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message. | |
| Modificada | Media (5) | 7.1% | — | Http Commander | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter. |