Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

CVE ID Publicado Severidad CVSS Descripción
CVE-2025-54413 2025-07-26 N/A 0.0 skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain…
CVE-2025-54412 2025-07-26 N/A 0.0 skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain…
CVE-2025-54385 2025-07-26 N/A 0.0 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions between…
CVE-2025-54380 2025-07-26 MEDIUM 6.5 Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6,…
CVE-2025-54378 2025-07-26 HIGH 8.3 HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of…
CVE-2025-54366 2025-07-26 N/A 0.0 FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185…
CVE-2025-50185 2025-07-26 N/A 0.0 DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to insufficient validation of…
CVE-2025-50184 2025-07-26 N/A 0.0 DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file…
CVE-2024-13507 2025-07-26 HIGH 7.5 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection…
CVE-2025-8175 2025-07-26 MEDIUM 6.5 A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of…
CVE-2025-8174 2025-07-26 MEDIUM 6.3 A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown…
CVE-2023-2274 2025-07-26 N/A 0.0 Rejected reason: This CVE assignment was considered invalid after investigation.
CVE-2025-8173 2025-07-25 HIGH 7.3 A vulnerability has been found in 1000 Projects ABC Courier Management System 1.0 and classified as critical. Affected by this…
CVE-2025-8172 2025-07-25 MEDIUM 6.3 A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System 1.0. Affected is an unknown function…
CVE-2025-8171 2025-07-25 MEDIUM 6.3 A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This issue affects some…
CVE-2025-8101 2025-07-25 N/A 0.0 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating…
CVE-2025-8170 2025-07-25 HIGH 8.8 A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. This vulnerability affects the function tcpcheck_net of the file…
CVE-2025-8169 2025-07-25 HIGH 8.8 A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function formSetWanPPTPcallback of the file…
CVE-2025-8166 2025-07-25 HIGH 7.3 A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is an unknown…
CVE-2025-52455 2025-07-25 MEDIUM 5.3 Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This…
CVE-2025-52454 2025-07-25 MEDIUM 5.3 Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing.…
CVE-2025-52453 2025-07-25 HIGH 8.2 Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing.…
CVE-2025-52452 2025-07-25 HIGH 8.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc…
CVE-2025-45960 2025-07-25 MEDIUM 6.1 Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web…
CVE-2025-45893 2025-07-25 MEDIUM 6.1 OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts.…
CVE-2025-45892 2025-07-25 MEDIUM 6.1 OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because…
CVE-2025-45406 2025-07-25 MEDIUM 6.1 A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scripts or HTML via a…
CVE-2025-29630 2025-07-25 HIGH 8.1 An issue in Gardyn 4 allows a remote attacker with the corresponding ssh private key can gain remote root access…
CVE-2025-45467 2025-07-25 HIGH 7.1 Unitree Go1
CVE-2025-44608 2025-07-25 MEDIUM 6.5 CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.
CVE-2025-29628 2025-07-25 HIGH 8.1 An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via a request
CVE-2024-48730 2025-07-25 MEDIUM 6.5 An issue in ETSI Open-Source MANO (OSM) v.14.x, v.15.x allows a remote attacker to escalate privileges via not imposing any…
CVE-2024-48729 2025-07-25 HIGH 7.1 An issue in ETSI Open-Source MANO (OSM) v.14.x, v.15.x allows a remote attacker to escalate privileges via the /osm/admin/v1/users component
CVE-2025-8197 2025-07-25 MEDIUM 5.5 A global buffer overflow vulnerability was found in the soup_header_name_to_string function in Libsoup. The `soup_header_name_to_string` function does not validate the…
CVE-2025-8168 2025-07-25 HIGH 8.8 A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the…
CVE-2025-8167 2025-07-25 LOW 3.5 A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by this vulnerability…
CVE-2025-46198 2025-07-25 HIGH 8.8 Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror…
CVE-2025-30135 2025-07-25 CRITICAL 9.4 An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It…
CVE-2025-52449 2025-07-25 HIGH 8.5 Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows…
CVE-2025-52447 2025-07-25 HIGH 8.1 Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation…
CVE-2025-8165 2025-07-25 MEDIUM 6.3 A vulnerability was found in code-projects Food Review System 1.0 and classified as critical. This issue affects some unknown processing…
CVE-2025-52448 2025-07-25 HIGH 8.1 Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data…
CVE-2025-52446 2025-07-25 HIGH 8.0 Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data…
CVE-2025-34139 2025-07-25 N/A 0.0 A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to…
CVE-2025-29631 2025-07-25 CRITICAL 9.8 An issue in Gardyn 4 allows a remote attacker execute arbitrary code
CVE-2025-34138 2025-07-25 N/A 0.0 A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow remote code execution or unauthorized…
CVE-2025-29629 2025-07-25 HIGH 8.8 An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary code via the Gardyn…
CVE-2025-8164 2025-07-25 MEDIUM 6.3 A vulnerability has been found in code-projects Public Chat Room 1.0 and classified as critical. This vulnerability affects unknown code…
CVE-2025-8163 2025-07-25 MEDIUM 6.3 A vulnerability, which was classified as critical, was found in deerwms deer-wms-2 up to 3.3. This affects an unknown part…
CVE-2025-5449 2025-07-25 MEDIUM 4.3 A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect…
« Anterior Página 70 de 3414 Siguiente »