Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.64% | — | Todo Filter Project Todo Filter | 21/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Todo Filter module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that toggle a task via unspecified vectors. | |
| Modificada | Media (4.3) | 2.5% | — | Websense Triton AP WEBWebsense Triton WEB FilterWebsense Triton WEB SecurityWebsense Triton WEB Security Gateway+1 | 25/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 and Web Security and Filter, Web Security Gateway, and Web Security Gateway Anywhere 7.8.3 before Hotfix 02 and 7.8.4 before Hotfix 01 allow remote attackers to inject arbitrary web script or HTML… | |
| Modificada | Alta (7.5) | 3.0% | — | Canonical Ubuntu LinuxLinuxfoundation Cups-filters | 24/3/2015 | 17/6/2026 | The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707. | |
| Modificada | Alta (7.5) | 3.0% | — | Divx DirectshowdemuxfilterDivx PlayerDivx WEB Player | 13/1/2015 | 17/6/2026 | Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow. | |
| Modificada | Baja (2.1) | 0.54% | — | Eset Personal Firewall Ndis Filter | 4/11/2014 | 17/6/2026 | The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensitive information from kernel memory via crafted IOCTL calls. | |
| Modificada | Media (5.4) | 0.27% | — | Cloudacl Safe Browser - THE WEB Filter | 11/10/2014 | 17/6/2026 | The Safe Browser - The Web Filter (aka com.cloudacl) application 1.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4) | 3.0% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as granting browse access to all IP addresses. | |
| Modificada | Media (4.3) | 2.9% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data. | |
| Modificada | Media (5.8) | 1.1% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707. | |
| Modificada | Alta (8.3) | 1.2% | — | Linuxfoundation Cups-filters | 17/4/2014 | 17/6/2026 | cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues." | |
| Modificada | Baja (3.5) | 1.3% | — | Websense Triton Unified Security CenterWebsense Triton WEB FilterWebsense Triton WEB SecurityWebsense Triton WEB Security Gateway+1 | 12/4/2014 | 17/6/2026 | The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext… | |
| Modificada | Media (4.4) | 0.31% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file. | |
| Modificada | Media (6.8) | 3.2% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 3.1% | — | Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 14/3/2014 | 17/6/2026 | Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (6.8) | 3.4% | — | Canonical Ubuntu LinuxLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file. | |
| Modificada | Alta (7.5) | 2.7% | — | Netfilter Iptables | 15/2/2014 | 16/6/2026 | extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant. | |
| Modificada | Alta (7.8) | 3.4% | — | Trustport Webfilter | 16/8/2013 | 16/6/2026 | Directory traversal vulnerability in help.php in Trustport Webfilter 5.5.0.2232 allows remote attackers to read arbitrary files via a .. (dot dot) in the hf parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Mobile4social Exposed Filter Data | 27/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Exposed Filter Data module 6.x-1.x before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 27% | — | Microsoft Office Filter PackMicrosoft VisioMicrosoft Visio Viewer | 13/3/2013 | 16/6/2026 | Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability." | |
| Modificada | Alta (7.5) | 6.3% | — | Bogofilter Project Bogofilter | 18/12/2012 | 16/6/2026 | Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an email containing a base64 string that is decoded to incomplete multibyte characters. | |
| Modificada | Media (4.3) | 1.4% | — | Hans Nilsson Video Filter | 6/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in video_filter.codecs.inc in the Video Filter module 6.x-2.x and 7.x-2.x for Drupal allows remote attackers to inject arbitrary web script or HTML via the EMBEDLOOKUP parameter for Blip.tv links. | |
| Modificada | Media (5) | 1.3% | — | Websense WEB FilterWebsense WEB Security | 26/8/2012 | 16/6/2026 | The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 106 and 7.x before 7.1 allow remote attackers to cause a denial of service (filtering outage) via a crafted URL. | |
| Modificada | Alta (7.5) | 3.5% | — | Websense WEB FilterWebsense WEB SecurityWebsense WEB Security GatewayWebsense WEB Security Gateway Anywhere | 23/8/2012 | 16/6/2026 | The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 before Hotfix 78, 7.5.1 before Hotfix 12, 7.6 before Hotfix 24, and 7.6.2 before Hotfix 12; Web Filter; Web Security Gateway; and Web Security Gateway Anywhere allows… | |
| Modificada | Media (5) | 1.6% | — | Websense WEB SecurityWebsense WEB Filter | 23/8/2012 | 16/6/2026 | Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue Coat appliance integration outage) via a long URL. | |
| Modificada | Media (5) | 1.4% | — | Websense WEB FilterWebsense WEB Security | 23/8/2012 | 16/6/2026 | Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. |