Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 1.2% | — | Finder Project Finder | 15/6/2015 | 17/6/2026 | Open redirect vulnerability in the finder_form_goto function in the Finder module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.4% | — | Sunhater Kcfinder | 3/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) file or (2) directory (folder) name of an uploaded file. | |
| Modificada | Alta (7.8) | 1.7% | — | Samsung FindmymobileSamsung Mobile | 24/10/2014 | 17/6/2026 | The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic. | |
| Modificada | Media (5.4) | 0.27% | — | Find Color Project Find Color | 16/10/2014 | 17/6/2026 | The Find Color (aka com.chudong.color) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Apploi JOB Search- Find Jobs | 23/9/2014 | 17/6/2026 | The Apploi Job Search- Find Jobs (aka com.apploi) application 4.19 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | NQ Easy Finder & Anti-theft | 9/9/2014 | 17/6/2026 | The Easy Finder & Anti-Theft (aka com.nqmobile.easyfinder) application 2.0.10.08 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Malware Finder Plugin Project Malware Finder | 1/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (4.3) | 2.7% | — | Danielb Finder | 8/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the autocomplete functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via the title of a node, a different vulnerability than CVE-2012-1561. | |
| Modificada | Media (4.3) | 3.0% | — | Danielb Finder | 8/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "checkbox and radio button functionalities." | |
| Modificada | Media (4.3) | 1.3% | — | Drinkedin Barfinder | 3/3/2014 | 17/6/2026 | The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geolocation information, by leveraging control over one of a number of adult sites, as demonstrated by (1)… | |
| Modificada | Media (4.3) | 1.4% | — | Alexey Sukhotin Elfinder | 24/6/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors. | |
| Modificada | Media (6) | 2.3% | — | Danielb Finder | 28/8/2012 | 16/6/2026 | The finder_import function in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote authenticated users with the administer finder permission to execute arbitrary PHP code via admin/build/finder/import. | |
| Modificada | Baja (2.1) | 1.0% | 💥 Exploit | Findingscience MOD Auth Openid | 25/7/2012 | 16/6/2026 | mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids. | |
| Modificada | Media (5) | 1.5% | — | Nicholas Thompson Node Quick Find | 10/4/2011 | 16/6/2026 | The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature. | |
| Modificada | Media (6.9) | 0.87% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable and a modified PATH environment variable, which is used during execution of the estasklight program, a different vulnerability than… | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of documents. | |
| Modificada | Media (5) | 1.3% | — | IBM Omnifind | 12/11/2010 | 16/6/2026 | IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveraging access to other pages on the web site. | |
| Modificada | Media (5) | 1.2% | — | IBM Omnifind | 12/11/2010 | 16/6/2026 | ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Omnifind | 12/11/2010 | 16/6/2026 | The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request to palette.do. | |
| Modificada | Alta (7.2) | 0.77% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Enterprise Edition before 8.5 FP6 allows remote attackers to execute arbitrary code via a long password. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue. | |
| Modificada | Media (6.8) | 1.2% | — | IBM Omnifind | 12/11/2010 | 16/6/2026 | Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by replaying a session ID (aka SID) value. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a saveNewUser action. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Omnifind | 12/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to inject arbitrary web script or HTML via the command parameter to the administration interface, as demonstrated by the command parameter to ESAdmin/collection.do. |