Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Ford Credit Account Manager | 2/10/2014 | 17/6/2026 | The Ford Credit Account Manager (aka com.fordcredit.accountmanager) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Starkvilleelectric SED Account | 30/9/2014 | 17/6/2026 | The SED Account (aka com.starkville.smartapps) application 1.153.0034 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Zoho Books - Accounting APP | 23/9/2014 | 17/6/2026 | The Zoho Books - Accounting App (aka com.zoho.books) application 3.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.3% | — | Frontaccounting | 5/6/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.3.21 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (3.6) | 0.38% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 16/4/2014 | 16/6/2026 | The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.4% | — | Ldap-account-manager Ldap Account Manager | 5/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Simone Tellini MOD Accounting | 30/9/2013 | 16/6/2026 | SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header. | |
| Modificada | Media (4.3) | 1.0% | — | Gnome Online AccountsCanonical Ubuntu Linux | 2/4/2013 | 16/6/2026 | Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue… | |
| Modificada | Media (4.3) | 1.4% | — | Gnome Online AccountsCanonical Ubuntu Linux | 2/4/2013 | 16/6/2026 | Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. | |
| Modificada | Baja (1.9) | 0.36% | — | RAY Stode Accountsservice | 22/7/2012 | 16/6/2026 | The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition. | |
| Modificada | Media (5) | 1.4% | — | Frontaccounting | 23/9/2011 | 16/6/2026 | FrontAccounting 2.3.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by reporting/includes/fpdi/fpdi2tcpdf_bridge.php and certain other files. | |
| Modificada | Alta (7.5) | 1.1% | — | Frontaccounting | 20/11/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x before 2.2 RC allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) bank_accounts.php, (2) currencies.php, (3) exchange_rates.php, (4) gl_account_types.php, and (5) gl_accounts.php in gl/manage/; and (6)… | |
| Modificada | Alta (7.5) | 1.1% | — | Frontaccounting | 20/11/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to various .inc and .php files in (1) reporting/, (2) sales/, (3) sales/includes/, (4) sales/includes/db/, (5) sales/inquiry/, (6) sales/manage/, (7)… | |
| Modificada | Alta (7.5) | 1.3% | — | Frontaccounting | 20/11/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7, and 2.2.x before 2.2 RC, allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/db/users_db.inc, and various other .inc and .php files under (2) admin/, (3) dimensions/, (4) gl/, (5) inventory/, (6)… | |
| Modificada | Alta (9.3) | 27% | 💥 Exploit | Microsoft Peachtree Accounting | 22/10/2008 | 16/6/2026 | Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers to execute arbitrary programs via the ExecutePreferredApplication method. | |
| Modificada | Media (6.8) | 1.1% | — | Frontaccounting | 1/10/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.12 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/logout.php or certain PHP scripts under (2) admin/, (3) dimensions/, (4) gl/, (5) inventory/, (6) manufacturing/, (7) purchasing/,… | |
| Modificada | Alta (9.3) | 3.6% | 💥 Exploit | Frontaccounting | 27/9/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/login.php and (2) includes/lang/language.php, different vectors than CVE-2007-4279. | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | Frontaccounting | 9/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | PHP Accounts | 22/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in PHPAccounts 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) Outgoing_Type_ID, (2) Outgoing_ID, (3) Project_ID, (4) Client_ID, (5) Invoice_ID, or (6) Vendor_ID parameter. | |
| Modificada | Alta (7.8) | 2.8% | 💥 Exploit | PHP Accounts | 22/6/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local files via unspecified manipulations of the page parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Ldap Account Manager | 3/4/2007 | 16/6/2026 | lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS). | |
| Modificada | Alta (7.2) | 0.33% | — | Ldap Account Manager | 3/4/2007 | 16/6/2026 | Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) before 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Dreamcost Dreamaccount | 2/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/index.php in DreamAccount 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | |
| Modificada | Media (5.1) | 18% | 💥 Exploit | Dreamcost Dreamaccount | 7/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the da_path parameter in the (1) auth.cookie.inc.php, (2) auth.header.inc.php, or (3) auth.sessions.inc.php scripts. | |
| Modificada | Media (6.8) | 1.3% | — | Accounting Receiving AND Inventory Administration Aria | 3/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in genmessage.php in Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows remote attackers to inject arbitrary web script or HTML via the Message Field (message parameter). |