408 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-4947
na1.foxitesign.foxit.com General
7.1
HIGH
EPSS
0.0%
2026 CWE-284 1 PoC

Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker to access or modify unauthorized resources by manipulating user-supplied object identifiers, potentially leading to forged signatures and compromising the integrity and authenticity of documents undergoing the signing process. The issue was caused by insufficient authorization validation on referenced resources during request processing.

CVE-2026-34414
xerteonlinetoolkits Web
7.1
HIGH
EPSS
0.2%
2026 CWE-22 2 PoCs

Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name parameter in rename commands is not sanitized for path traversal sequences. Attackers can supply a name value containing directory traversal sequences to move files from project media directories to arbitrary locations on the filesystem, potentially overwriting application files, achieving stored cross-site scripting, or combining with other vulnerabilities to achieve unauthenticated remote code execution by movi

CVE-2026-40039
Pachno General
7.1
HIGH
EPSS
0.0%
2026 CWE-305 1 PoC

Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to values to conduct phishing attacks and steal user credentials.

CVE-2026-41465
ProjeQtor Web
7.1
HIGH
EPSS
0.2%
2026 CWE-22 1 PoC

ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the logname parameter to read arbitrary .log files accessible to the web server process on the filesystem.

CVE-2026-5394
pimcore Database
7.0
HIGH
EPSS
0.0%
2026 CWE-89 1 PoC

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.

CVE-2026-5656
Wireshark General
7.0
HIGH
EPSS
0.0%
2026 CWE-22 1 PoC

Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

CVE-2026-21253
Windows 10 Version 1607 Windows
7.0
HIGH
EPSS
0.1%
2026 CWE-416 2 PoCs

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

CVE-2026-8207
gibbon Web Database
7.0
HIGH
EPSS
0.0%
2026 CWE-89 1 PoC

Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2d1abadb/modules/Tracking/graphing.php#L145 feature. Successful exploitation requires Teacher or higher privileges. Exploitation could result in unintended read/write activities to the underlying database.