Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

380 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.64%—Todo Filter Project Todo Filter21/4/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Todo Filter module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that toggle a task via unspecified vectors.
ModificadaMedia (4.3)2.5%—Websense Triton AP WEBWebsense Triton WEB FilterWebsense Triton WEB SecurityWebsense Triton WEB Security Gateway+125/3/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 and Web Security and Filter, Web Security Gateway, and Web Security Gateway Anywhere 7.8.3 before Hotfix 02 and 7.8.4 before Hotfix 01 allow remote attackers to inject arbitrary web script or HTML…
ModificadaAlta (7.5)3.0%—Canonical Ubuntu LinuxLinuxfoundation Cups-filters24/3/201517/6/2026
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.
ModificadaAlta (7.5)3.0%—Divx DirectshowdemuxfilterDivx PlayerDivx WEB Player13/1/201517/6/2026
Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow.
ModificadaBaja (2.1)0.54%—Eset Personal Firewall Ndis Filter4/11/201417/6/2026
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensitive information from kernel memory via crafted IOCTL calls.
ModificadaMedia (5.4)0.27%—Cloudacl Safe Browser - THE WEB Filter11/10/201417/6/2026
The Safe Browser - The Web Filter (aka com.cloudacl) application 1.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4)3.0%—Linuxfoundation Cups-filters22/6/201417/6/2026
cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as granting browse access to all IP addresses.
ModificadaMedia (4.3)2.9%—Linuxfoundation Cups-filters22/6/201417/6/2026
The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.
ModificadaMedia (5.8)1.1%—Linuxfoundation Cups-filters22/6/201417/6/2026
The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.
ModificadaAlta (8.3)1.2%—Linuxfoundation Cups-filters17/4/201417/6/2026
cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues."
ModificadaBaja (3.5)1.3%—Websense Triton Unified Security CenterWebsense Triton WEB FilterWebsense Triton WEB SecurityWebsense Triton WEB Security Gateway+112/4/201417/6/2026
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext…
ModificadaMedia (4.4)0.31%—Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters14/3/201417/6/2026
The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file.
ModificadaMedia (6.8)3.2%—Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters14/3/201417/6/2026
Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.
ModificadaMedia (6.8)3.1%—Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora14/3/201417/6/2026
Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
ModificadaMedia (6.8)3.4%—Canonical Ubuntu LinuxLinuxfoundation Cups-filters14/3/201417/6/2026
Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.
ModificadaAlta (7.5)2.7%—Netfilter Iptables15/2/201416/6/2026
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
ModificadaAlta (7.8)3.4%—Trustport Webfilter16/8/201316/6/2026
Directory traversal vulnerability in help.php in Trustport Webfilter 5.5.0.2232 allows remote attackers to read arbitrary files via a .. (dot dot) in the hf parameter.
ModificadaMedia (4.3)1.2%—Mobile4social Exposed Filter Data27/6/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Exposed Filter Data module 6.x-1.x before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)27%—Microsoft Office Filter PackMicrosoft VisioMicrosoft Visio Viewer13/3/201316/6/2026
Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."
ModificadaAlta (7.5)6.3%—Bogofilter Project Bogofilter18/12/201216/6/2026
Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an email containing a base64 string that is decoded to incomplete multibyte characters.
ModificadaMedia (4.3)1.4%—Hans Nilsson Video Filter6/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in video_filter.codecs.inc in the Video Filter module 6.x-2.x and 7.x-2.x for Drupal allows remote attackers to inject arbitrary web script or HTML via the EMBEDLOOKUP parameter for Blip.tv links.
ModificadaMedia (5)1.3%—Websense WEB FilterWebsense WEB Security26/8/201216/6/2026
The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 106 and 7.x before 7.1 allow remote attackers to cause a denial of service (filtering outage) via a crafted URL.
ModificadaAlta (7.5)3.5%—Websense WEB FilterWebsense WEB SecurityWebsense WEB Security GatewayWebsense WEB Security Gateway Anywhere23/8/201216/6/2026
The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 before Hotfix 78, 7.5.1 before Hotfix 12, 7.6 before Hotfix 24, and 7.6.2 before Hotfix 12; Web Filter; Web Security Gateway; and Web Security Gateway Anywhere allows…
ModificadaMedia (5)1.6%—Websense WEB SecurityWebsense WEB Filter23/8/201216/6/2026
Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue Coat appliance integration outage) via a long URL.
ModificadaMedia (5)1.4%—Websense WEB FilterWebsense WEB Security23/8/201216/6/2026
Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Orbitaley — Vulnerabilidades