Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 1.2% | — | Pixelite Events Manager | 12/4/2019 | 17/6/2026 | The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI. | |
| Modificada | Alta (7.8) | 0.45% | — | Skydevices SKY Elite 6.0l+ Firmware | 28/12/2018 | 17/6/2026 | The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys contains a pre-installed platform app with a package name of com.fw.upgrade.sysoper (versionCode=238, versionName=2.3.8) that contains an exported broadcast receiver app… | |
| Modificada | Crítica (9) | 1.4% | — | Runelite | 20/12/2018 | 17/6/2026 | runelite version <= runelite-parent-1.4.23 contains a XML External Entity (XXE) vulnerability in Man in the middle runscape services call that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. | |
| Modificada | Alta (7.5) | 1.1% | — | Eliteshippertoken Project Eliteshippertoken | 5/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for EliteShipperToken (ESHIP), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (5.4) | 1.5% | — | Pixelite Events Manager | 14/5/2018 | 17/6/2026 | Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 1.0% | — | Pixelite Events Manager | 26/3/2018 | 17/6/2026 | The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature. | |
| Modificada | Alta (7.9) | 0.42% | — | HP 700 Series FirmwareHP 800 Series FirmwareHP Z240 FirmwareHP Z238 Firmware+3 | 4/3/2016 | 17/6/2026 | Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access. | |
| Modificada | Alta (8.8) | 2.8% | — | Lacie Lac9000436u FirmwareLacie Lac9000464u FirmwareSeagate Wireless Mobile StorageSeagate Wireless Plus Mobile Storage+1 | 31/12/2015 | 17/6/2026 | Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session. | |
| Modificada | Alta (7.5) | 3.2% | — | Seagate Goflex SatteliteSeagate Wireless Mobile StorageSeagate Wireless Plus Mobile StorageLacie Lac9000436u Firmware+1 | 31/12/2015 | 17/6/2026 | Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to read arbitrary files via a full pathname in a download request during a Wi-Fi session. | |
| Modificada | Crítica (9.8) | 4.2% | — | Seagate Wireless Mobile StorageSeagate Wireless Plus Mobile StorageLacie Lac9000436u FirmwareLacie Lac9000464u Firmware+1 | 31/12/2015 | 17/6/2026 | Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session. | |
| Modificada | Alta (7.8) | 7.1% | — | HP Hspa+ Gobi 4GHP Lt4112 LTEHP Elite X2 1010 G2HP Elitebook 1040 G1+35 | 27/8/2015 | 17/6/2026 | The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial of service, or execute arbitrary code, via unspecified vectors. | |
| Modificada | Media (6.9) | 0.51% | — | HP Hspa+ Gobi 4GHP Lt4112 LTEHP Elite X2 1010 G2HP Elitebook 1040 G1+35 | 27/8/2015 | 17/6/2026 | The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.62% | — | HP Elitepad | 24/4/2013 | 16/6/2026 | HP ElitePad 900 PCs with BIOS F.0x before F.01 Update 1.0.0.8 do not enable the Secure Boot feature, which allows local users to bypass intended BIOS restrictions and boot unintended operating systems via unspecified vectors. | |
| Modificada | Media (5.8) | 1.1% | — | Activision Call OF Duty Elite | 22/1/2013 | 16/6/2026 | Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to obtain sensitive information via a Man-in-the-Middle (MITM) attack. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Elite-board Elite Bulletin Board | 12/1/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Elite Bulletin Board before 2.1.22 allow remote attackers to execute arbitrary SQL commands via the PATH_INFO to (a) checkuser.php, (b) groups.php, (c) index.php, (d) login.php, (e) quicklogin.php, (f)… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Eliteweaver Xclick Cart | 1/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the shopping_url parameter. | |
| Modificada | Alta (7.4) | 0.94% | — | Elitecore Cyberoam Unified Threat Management | 9/7/2012 | 16/6/2026 | The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Cyberoam_SSL_CA certificate in a list of… | |
| Modificada | Media (6) | 0.84% | 💥 Exploit | Elitecore Cyberoam Unified Threat Management | 4/1/2012 | 16/6/2026 | SQL injection vulnerability in corporate/Controller in Elitecore Technologies Cyberoam UTM before 10.01.2 build 059 allows remote authenticated administrators to execute arbitrary SQL commands via the tableid parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Eliteladders Elite Gaming Ladders | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Eliteladders Elite Gaming Ladders | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Eliteladders Elite Gaming Ladders | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Joomla COM Elite Experts | 9/10/2011 | 16/6/2026 | SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showExpertProfileDetailed action to index.php. | |
| Modificada | Baja (2.1) | 0.33% | — | Kingston Datatraveler BlackboxKingston Datatraveler EliteKingston Datatraveler Secure | 7/1/2010 | 16/6/2026 | Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data… | |
| Modificada | Media (4.6) | 0.36% | — | Kingston Datatraveler BlackboxKingston Datatraveler EliteKingston Datatraveler Secure | 7/1/2010 | 16/6/2026 | Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining… | |
| Modificada | Baja (2.1) | 0.48% | — | Kingston Datatraveler BlackboxKingston Datatraveler EliteKingston Datatraveler Secure | 7/1/2010 | 16/6/2026 | Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive… |