Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.41% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+181 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | |
| Modificada | Alta (8.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 Firmware+124 | 13/4/2023 | 17/6/2026 | Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Flight Booking Management System Project Online Flight Booking Management System | 13/1/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Flight Booking Management System. This affects an unknown part of the file review_search.php of the component POST Parameter Handler. The manipulation of the argument txtsearch leads to sql injection. It is possible to initiate the attack… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Flight Booking Management System Project Online Flight Booking Management System | 13/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Flight Booking Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file judge_panel.php. The manipulation of the argument subevent_id leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.73% | — | Online Flight Booking Management System Project Online Flight Booking Management System | 12/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Flight Booking Management System. This issue affects some unknown processing of the file add_contestant.php. The manipulation of the argument add_contestant leads to sql injection. The attack may be initiated remotely. The… | |
| Modificada | Media (5.5) | 0.25% | — | Flightradar24 Flight Tracker | 2/6/2022 | 17/6/2026 | An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application and extract their API keys. | |
| Modificada | Baja (2.4) | 0.24% | — | Phillips Gemini 882300 FirmwarePhillips Gemini 882160 FirmwarePhillips Gemini 882400 FirmwarePhillips Gemini 882390 Firmware+7 | 23/3/2022 | 17/6/2026 | Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control. | |
| Modificada | Alta (7.2) | 1.5% | — | Zavedil Flightlog | 7/6/2021 | 17/6/2026 | The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users | |
| Modificada | Media (6.1) | 0.83% | — | Getflightpath Flightpath | 20/8/2019 | 17/6/2026 | FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions. | |
| Modificada | Alta (7.5) | 3.7% | — | Sigil-ebook SigilFlightcrew Project FlightcrewCanonical Ubuntu Linux | 31/7/2019 | 17/6/2026 | Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. | |
| Modificada | Media (5.3) | 63% | 💥 Exploit | Getflightpath Flightpath | 10/7/2019 | 17/6/2026 | FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module. | |
| Modificada | Alta (7.8) | 1.6% | — | Flightcrew Project FlightcrewCanonical Ubuntu Linux | 4/7/2019 | 17/6/2026 | FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. | |
| Modificada | Media (5.5) | 1.0% | — | Flightcrew Project Flightcrew | 28/6/2019 | 17/6/2026 | An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library. | |
| Modificada | Media (6.1) | 0.86% | — | Flightairmap | 20/8/2018 | 17/6/2026 | FlightAirMap version <=v1.0-beta.21 contains a Cross Site Scripting (XSS) vulnerability in GET variable used within registration sub menu page that can result in unauthorised actions and access to data, stealing session information. This vulnerability appears to have been fixed in after commit 22b09a3. | |
| Modificada | Crítica (9.8) | 1.00% | — | Flightsimlabs A320-x | 20/2/2018 | 17/6/2026 | The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHandler3.ashx if a pirated serial number has been entered, which allows remote attackers to obtain sensitive information, e.g., by sniffing the network for cleartext HTTP… | |
| Modificada | Alta (7.5) | 1.1% | — | Flightgear | 27/8/2017 | 17/6/2026 | In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the contents of the global Property Tree. | |
| Modificada | Alta (7.5) | 1.4% | — | Flightgear | 12/5/2017 | 17/6/2026 | In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage files belonging to the user. Both this… | |
| Modificada | Media (6.1) | 0.84% | — | Flightairmap | 2/3/2017 | 17/6/2026 | An issue was discovered in FlightAirMap v1.0-beta.10. The vulnerability exists due to insufficient filtration of user-supplied data in multiple parameters passed to several *-sub-menu.php pages. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | |
| Modificada | Alta (7.5) | 3.2% | — | Debian LinuxFedoraproject FedoraFlightgear | 22/2/2017 | 17/6/2026 | The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script. | |
| Modificada | Media (5.4) | 0.27% | — | 133 Flight Manager | 21/10/2014 | 17/6/2026 | The Flight Manager (aka com.flightmanager.view) application 4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Tiket.com Hotel & Flight | 21/10/2014 | 17/6/2026 | The Tiket.com Hotel & Flight (aka com.tiket.gits) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 6.5% | — | FlightgearSimgear | 17/6/2012 | 16/6/2026 | Multiple buffer overflows in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long string in a rotor tag of an aircraft xml model to the Rotor::getValueforFGSet function in… | |
| Modificada | Alta (9.3) | 6.0% | — | FlightgearSimgear | 17/6/2012 | 16/6/2026 | Multiple format string vulnerabilities in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in certain data chunk values in an aircraft xml model to (1)… | |
| Modificada | Alta (9.3) | 2.9% | — | Nasa Goddard Space Flight Center Common Data Format | 18/8/2009 | 16/6/2026 | Multiple buffer overflows in NASA Common Data Format (CDF) allow context-dependent attackers to execute arbitrary code, as demonstrated using (1) an array index error in the ReadAEDRList64 function, and other errors in the (2) SearchForRecord_r_64, (3) LastRecord64, (4) CDFsel64, and other unspecified functions. | |
| Modificada | Alta (7.5) | 3.9% | — | Nasa Goddard Space Flight Center Common Data Format | 6/5/2008 | 16/6/2026 | Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags. |