Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 2.6% | — | Infinixauthority HOT X507 FirmwareInfinixauthority HOT 2 X510 FirmwareInfinixauthority Zero X506 FirmwareInfinixauthority Zero 2 X509 Firmware+15 | 13/7/2018 | 17/6/2026 | Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple techniques used to hide the execution of this binary. This behavior could be described as a rootkit. This binary, which resides as /system/bin/debugs, runs with root… | |
| Modificada | Media (4.4) | 0.33% | — | SAP Dynamic Authorization Management | 10/7/2018 | 17/6/2026 | Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs. | |
| Modificada | Media (4.7) | 0.16% | — | Unisys Stealth Authorization Server | 30/5/2018 | 17/6/2026 | In Stealth Authorization Server before 3.3.017.0 in Unisys Stealth Solution, an encryption key may be left in memory. | |
| Modificada | Alta (7.1) | 1.2% | — | Powerdns Authoritative | 23/1/2018 | 17/6/2026 | An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing… | |
| Modificada | Alta (8.8) | 0.68% | — | Jenkins Role-based Authorization Strategy | 5/10/2017 | 17/6/2026 | Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user, or to remove the authorization configuration, preventing legitimate access to Jenkins. | |
| Modificada | Media (6.8) | 3.8% | — | Opensuse LeapOpensusePowerdns Authoritative Server | 26/9/2016 | 17/6/2026 | PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response. | |
| Modificada | Alta (7.5) | 63% | — | Powerdns Authoritative | 21/9/2016 | 17/6/2026 | PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query. | |
| Modificada | Alta (7.5) | 31% | — | Powerdns Authoritative | 21/9/2016 | 17/6/2026 | PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname. | |
| Modificada | Media (5.5) | 0.94% | — | Apple Ibooks Author | 5/4/2016 | 17/6/2026 | Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (5) | 67% | — | Powerdns Authoritative | 17/11/2015 | 17/6/2026 | PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets. | |
| Modificada | Alta (7.8) | 11% | — | Powerdns AuthoritativePowerdns Recursor | 2/11/2015 | 17/6/2026 | The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a long name that refers to itself. NOTE: this… | |
| Modificada | Alta (7.8) | 82% | — | Powerdns AuthoritativeFedoraproject FedoraPowerdns Recursor | 18/5/2015 | 17/6/2026 | The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself. | |
| Modificada | Baja (3.5) | 0.94% | — | Nodeauthor Project Nodeauthor | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the nodeauthor module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a Profile2 field in a provided block. | |
| Modificada | Media (5.4) | 0.27% | — | Booksellerscanada Free Canadian Author Previews | 21/10/2014 | 17/6/2026 | The Free Canadian Author Previews (aka com.booksellerscanada.authorpreview) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Authorsontourlive Authors ON Tour - Live! | 20/10/2014 | 17/6/2026 | The Authors On Tour - Live! (aka com.appmakr.app122286) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Lincolnloop Authorize.net Echeck ModuleZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The Authorize.Net eCheck module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Irata Authorize.net ModuleUbercart | 4/11/2012 | 16/6/2026 | The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Harald Ponce DE Leon Authorize.netOscommerce | 4/11/2012 | 16/6/2026 | The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (6.9) | 0.36% | — | Cyberlink Streamauthor | 6/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in CyberLink StreamAuthor 4.0 build 3308 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .sta or .stp file. NOTE: the provenance of this… | |
| Modificada | Media (6.9) | 0.40% | — | E-press ONE Office Author | 6/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in e-press ONE Office Author allow local users to gain privileges via a Trojan horse (1) java_msci.dll or (2) msci_java.dll file in the current working directory, as demonstrated by a directory that contains a .psw file. NOTE: some of these details are obtained from third… | |
| Modificada | Baja (3.5) | 1.7% | — | Authoring Html 6.x-1.0 | 27/6/2012 | 16/6/2026 | classes/Filter/WhitelistedExternalFilter.php in the Authoring HTML module 6.x-1.x before 6.x-1.1 for Drupal does not properly validate sources with the host white list, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks. | |
| Modificada | Media (5) | 4.8% | — | Powerdns Authoritative Server | 17/2/2012 | 16/6/2026 | common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response. | |
| Modificada | Media (5) | 14% | 💥 Exploit | Thorsten Riess COM Jcollection | 8/3/2010 | 16/6/2026 | Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Cbauthority | 16/9/2009 | 16/6/2026 | SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_product action. | |
| Modificada | Media (6.8) | 0.93% | 💥 Exploit | Anoochit Chalothorn Tiny Blogr | 28/4/2009 | 16/6/2026 | SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field). NOTE: some of these details are obtained from third party information. |