Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.21%—Zenar Content Management SystemAI17/5/202617/6/2026
Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.php endpoint, which reflects unsanitized…
ModificadaAlta (7.3)0.40%—Rocketsoftware Zena30/7/20255/7/2026
Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
AnalizadaMedia (4.8)0.37%—Tribalsystems Zenario2/10/202417/6/2026
Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.
AnalizadaMedia (4.8)0.36%—Tribalsystems Zenario2/10/202417/6/2026
Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.
AplazadaCrítica (9.8)0.95%—Zenario Twig SnippetAITribalsystems ZenarioAI4/5/202417/6/2026
Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.
AplazadaMedia (6.5)0.55%—Tribalsystems ZenarioAI4/5/202417/6/2026
The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)
AnalizadaAlta (8.8)0.60%—Mhasistemas Armhazena15/3/202417/6/2026
A vulnerability classified as critical was found in MHA Sistemas arMHAzena 9.6.0.0. This vulnerability affects unknown code of the component Executa Page. The manipulation of the argument Companhia/Planta/Agente de/Agente até leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
AplazadaBaja (3.5)0.48%—Mhasistemas ArmhazenaAI15/3/202417/6/2026
A vulnerability classified as problematic has been found in MHA Sistemas arMHAzena 9.6.0.0. This affects an unknown part of the component Cadastro Page. The manipulation of the argument Query leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
ModificadaMedia (5.4)0.66%—Tribalsystems Zenario25/10/202317/6/2026
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.
ModificadaMedia (5.4)0.54%—Tribalsystems Zenario6/10/202317/6/2026
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout.
ModificadaMedia (5.4)0.55%—Tribalsystems Zenario6/10/202317/6/2026
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.
ModificadaMedia (4.8)0.44%—Tribalsystems Zenario28/8/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.
ModificadaCrítica (9.8)1.2%—Tribalsystems Zenario30/11/202217/6/2026
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario30/11/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The exploit has been disclosed to the public…
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario16/11/202217/6/2026
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario16/11/202217/6/2026
Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario16/11/202217/6/2026
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles.
ModificadaMedia (5.4)0.47%—Tribalsystems Zenario16/11/202217/6/2026
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module.
ModificadaMedia (6.1)0.43%—Tribalsystems Zenario2/11/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the…
ModificadaMedia (6.1)1.2%—Rocketsoftware Ags-zena17/6/20229/7/2026
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
ModificadaAlta (7.5)0.58%—Rocketsoftware Ags-zena17/6/20229/7/2026
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.
ModificadaCrítica (9.8)1.1%—Rocketsoftware Ags-zena17/6/20229/7/2026
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
ModificadaAlta (7.2)2.5%—Tribalsystems Zenario14/3/202217/6/2026
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.
ModificadaMedia (4.8)0.51%—Tribalsystems Zenario14/3/202217/6/2026
Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicious files to victims and steals victim's cookie leads to account takeover. The person viewing the image of a contact can be victim of XSS.
ModificadaAlta (7.2)1.5%—Tribalsystems Zenario24/2/202217/6/2026
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.