Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.2% | — | Debian LinuxMuttNeomuttCanonical Ubuntu Linux | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID. | |
| Modificada | Media (5.3) | 3.3% | — | Debian LinuxMuttNeomuttCanonical Ubuntu Linux | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name. | |
| Modificada | Crítica (9.8) | 6.2% | — | MuttNeomuttCanonical Ubuntu LinuxDebian Linux+6 | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription. | |
| Modificada | Crítica (9.8) | 3.7% | — | MuttNeomuttCanonical Ubuntu LinuxDebian Linux | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow. | |
| Modificada | Crítica (9.8) | 4.0% | — | MuttNeomuttCanonical Ubuntu LinuxDebian Linux | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow. | |
| Modificada | Crítica (9.8) | 3.2% | — | MuttNeomuttCanonical Ubuntu LinuxDebian Linux | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size. | |
| Modificada | Crítica (9.8) | 5.0% | — | MuttNeomuttDebian LinuxCanonical Ubuntu Linux | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field. | |
| Modificada | Crítica (9.8) | 3.2% | — | Debian LinuxMuttNeomuttCanonical Ubuntu Linux | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Neojoomla Neorecruit | 17/2/2018 | 17/6/2026 | SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI. | |
| Modificada | Media (5.9) | 0.85% | — | Banconeon Neon | 17/1/2018 | 17/6/2026 | The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Crítica (9.8) | 2.6% | — | Hancom Thinkfree Office NEO | 17/1/2018 | 17/6/2026 | Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands when performing the hyperlink Attributes in document. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (5.9) | 9.8% | 💥 PoC | Infineon Trusted Platform FirmwareInfineon RSA Library | 16/10/2017 | 17/6/2026 | The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection… | |
| Modificada | Media (6.6) | 0.54% | — | Infineon S-gold 2 PMB 8876 | 7/8/2017 | 17/6/2026 | A Stack-Based Buffer Overflow issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35, Infiniti 2014-2016 QX60, Infiniti 2014-2016 QX60 Hybrid, Infiniti 2014-2015 QX50, Infiniti… | |
| Modificada | Alta (8.8) | 2.2% | — | Infineon S-gold 2 PMB 8876 | 7/8/2017 | 17/6/2026 | An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35, Infiniti 2014-2016 QX60, Infiniti 2014-2016 QX60… | |
| Modificada | Crítica (9.8) | 3.9% | — | Akeneo Product Information Management | 17/7/2017 | 17/6/2026 | Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution. | |
| Modificada | Alta (7.8) | 1.7% | — | Hancom Hangul Word ProcessorHancom Thinkfree Office NEO | 24/5/2017 | 17/6/2026 | An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO 9.6.1.4902. A specially crafted document stream can cause an integer underflow resulting in a buffer overflow which can lead to code execution under the context of the… | |
| Modificada | Media (4) | 1.6% | — | Neojapan Desknet NEO | 5/9/2015 | 17/6/2026 | Directory traversal vulnerability in zhtml.cgi in NEOJAPAN desknet NEO 2.0R1.0 through 2.5R1.4 allows remote authenticated users to read arbitrary files via a crafted parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Zoneo-soft Phptraffica | 14/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Php/stats/statsRecent.inc.php in phpTrafficA 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header to index.php. | |
| Modificada | Media (6.5) | 0.89% | — | Typo3 Neos | 1/4/2015 | 17/6/2026 | TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.8% | — | Zoneo-soft Phptraffica | 16/12/2014 | 17/6/2026 | SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via a User-Agent HTTP header. | |
| Modificada | Media (5.4) | 0.27% | — | Neorcha Usek | 29/9/2014 | 17/6/2026 | The USEK (aka com.university.usek) application 1.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 1.3% | — | Neo4j | 29/4/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary code, as demonstrated by a request to (1) db/data/ext/GremlinPlugin/graphdb/execute_script or (2) db/manage/server/console/. | |
| Modificada | Media (5.8) | 1.4% | — | Skyarts Neofiler | 12/1/2014 | 17/6/2026 | Directory traversal vulnerability in the NeoFiler application 5.4.3 and earlier, NeoFiler Free application 5.4.3 and earlier, and NeoFiler Lite application 2.4.2 and earlier for Android allows attackers to overwrite or create arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Digineo Thumbshooter | 9/4/2013 | 16/6/2026 | lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. |