Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

265 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)2.6%—Infinixauthority HOT X507 FirmwareInfinixauthority HOT 2 X510 FirmwareInfinixauthority Zero X506 FirmwareInfinixauthority Zero 2 X509 Firmware+1513/7/201817/6/2026
Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple techniques used to hide the execution of this binary. This behavior could be described as a rootkit. This binary, which resides as /system/bin/debugs, runs with root…
ModificadaMedia (4.4)0.33%—SAP Dynamic Authorization Management10/7/201817/6/2026
Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.
ModificadaMedia (4.7)0.16%—Unisys Stealth Authorization Server30/5/201817/6/2026
In Stealth Authorization Server before 3.3.017.0 in Unisys Stealth Solution, an encryption key may be left in memory.
ModificadaAlta (7.1)1.2%—Powerdns Authoritative23/1/201817/6/2026
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing…
ModificadaAlta (8.8)0.68%—Jenkins Role-based Authorization Strategy5/10/201717/6/2026
Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user, or to remove the authorization configuration, preventing legitimate access to Jenkins.
ModificadaMedia (6.8)3.8%—Opensuse LeapOpensusePowerdns Authoritative Server26/9/201617/6/2026
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.
ModificadaAlta (7.5)63%—Powerdns Authoritative21/9/201617/6/2026
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.
ModificadaAlta (7.5)31%—Powerdns Authoritative21/9/201617/6/2026
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
ModificadaMedia (5.5)0.94%—Apple Ibooks Author5/4/201617/6/2026
Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
ModificadaMedia (5)67%—Powerdns Authoritative17/11/201517/6/2026
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
ModificadaAlta (7.8)11%—Powerdns AuthoritativePowerdns Recursor2/11/201517/6/2026
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a long name that refers to itself. NOTE: this…
ModificadaAlta (7.8)82%—Powerdns AuthoritativeFedoraproject FedoraPowerdns Recursor18/5/201517/6/2026
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
ModificadaBaja (3.5)0.94%—Nodeauthor Project Nodeauthor21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the nodeauthor module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a Profile2 field in a provided block.
ModificadaMedia (5.4)0.27%—Booksellerscanada Free Canadian Author Previews21/10/201417/6/2026
The Free Canadian Author Previews (aka com.booksellerscanada.authorpreview) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Authorsontourlive Authors ON Tour - Live!20/10/201417/6/2026
The Authors On Tour - Live! (aka com.appmakr.app122286) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.8)0.57%—Lincolnloop Authorize.net Echeck ModuleZen-cart ZEN Cart4/11/201216/6/2026
The Authorize.Net eCheck module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ModificadaMedia (5.8)0.57%—Irata Authorize.net ModuleUbercart4/11/201216/6/2026
The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ModificadaMedia (5.8)0.57%—Harald Ponce DE Leon Authorize.netOscommerce4/11/201216/6/2026
The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ModificadaMedia (6.9)0.36%—Cyberlink Streamauthor6/9/201216/6/2026
Multiple untrusted search path vulnerabilities in CyberLink StreamAuthor 4.0 build 3308 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .sta or .stp file. NOTE: the provenance of this…
ModificadaMedia (6.9)0.40%—E-press ONE Office Author6/9/201216/6/2026
Multiple untrusted search path vulnerabilities in e-press ONE Office Author allow local users to gain privileges via a Trojan horse (1) java_msci.dll or (2) msci_java.dll file in the current working directory, as demonstrated by a directory that contains a .psw file. NOTE: some of these details are obtained from third…
ModificadaBaja (3.5)1.7%—Authoring Html 6.x-1.027/6/201216/6/2026
classes/Filter/WhitelistedExternalFilter.php in the Authoring HTML module 6.x-1.x before 6.x-1.1 for Drupal does not properly validate sources with the host white list, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks.
ModificadaMedia (5)4.8%—Powerdns Authoritative Server17/2/201216/6/2026
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.
ModificadaMedia (5)14%💥 ExploitThorsten Riess COM Jcollection8/3/201016/6/2026
Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)0.99%💥 ExploitCbauthority16/9/200916/6/2026
SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_product action.
ModificadaMedia (6.8)0.93%💥 ExploitAnoochit Chalothorn Tiny Blogr28/4/200916/6/2026
SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field). NOTE: some of these details are obtained from third party information.
Orbitaley — Vulnerabilidades