Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

313 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.3%—Sandstorm6/2/201817/6/2026
Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip function doesn't filter Line Feed (\n) characters in a directory name.
ModificadaCrítica (9.8)3.0%—Sandstorm6/2/201817/6/2026
A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field.
ModificadaMedia (6.5)1.4%—Sandstorm6/2/201817/6/2026
The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to cause a denial of service by launching a fork bomb in the sandbox, or by using a large amount of disk space.
ModificadaAlta (7.5)5.3%—Apache Storm30/10/201717/6/2026
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.
ModificadaAlta (8.8)4.9%—Apache Storm9/8/201717/6/2026
It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other…
ModificadaCrítica (9.8)14%—Apache Storm13/1/201717/6/2026
The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (5.4)0.27%—Sunstormgames Donut Maker9/9/201417/6/2026
The Donut Maker (aka com.sunstorm.android.donut) application 1.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5)1.8%—Breakingpointsystems Breakingpoint Storm Appliance CTMBreakingpointsystems Breakingpoint Storm Appliance12/8/201216/6/2026
The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.
ModificadaMedia (5)1.8%—Breakingpointsystems Breakingpoint Storm Appliance CTMBreakingpointsystems Breakingpoint Storm Appliance12/8/201216/6/2026
The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive information by downloading a .tgz file.
ModificadaAlta (10)1.7%—Ucweb Ucmobile Blovestorm14/3/201216/6/2026
Unspecified vulnerability in the UCMobile BloveStorm (com.blovestorm) application 2.2.0 and 3.2.1 for Android has unknown impact and attack vectors.
ModificadaBaja (2.1)0.66%—Speedtech Storm7/6/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) phone, or (3) im parameter in a stormperson action to index.php. NOTE: the…
ModificadaBaja (2.1)1.5%—Speedtech Storm1/6/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) address, (3) city, (4) provstate (aka state), (5) phone, or (6) taxid…
ModificadaAlta (7.5)1.0%—Typo3 Brainstorming19/3/201016/6/2026
SQL injection vulnerability in the Brainstorming extension 0.1.8 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5)1.3%—Speedtech Storm31/12/200916/6/2026
The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecified vectors.
ModificadaAlta (9.3)5.6%💥 ExploitBaofeng Storm27/7/200916/6/2026
Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist file.
ModificadaAlta (9.3)7.5%💥 ExploitBaofeng Storm28/5/200916/6/2026
Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009.
ModificadaAlta (9.3)33%💥 ExploitBaofeng Storm11/5/200916/6/2026
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party…
ModificadaMedia (6)0.85%—Drupal Storm2/3/200916/6/2026
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.00%💥 ExploitStormboards Aaronnemisis Stormboards26/12/200816/6/2026
SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (9.3)12%💥 ExploitGuliverkli Media Player ClassicMympc Cd-stormVerycd Stormplayer18/9/200716/6/2026
Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi…
ModificadaAlta (9.3)3.3%—Baofeng Storm18/9/200716/6/2026
Multiple buffer overflows in a certain ActiveX control in sparser.dll in Baofeng Storm 2.8 and earlier allow remote attackers to execute arbitrary code via malformed input in an unknown set of arguments or property values, a different DLL than CVE-2007-4816. NOTE: the provenance of this information is unknown; the…
ModificadaAlta (9.3)4.4%—Guliverkli Media Player ClassicMympc Cd-stormVerycd Stormplayer18/9/200716/6/2026
Multiple integer overflows in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain…
ModificadaAlta (7.5)9.2%💥 ExploitBaofeng Storm11/9/200716/6/2026
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a long first argument to the advancedOpen method; a long argument to the (5) isDVDPath or (6) rawParse method; or (7) a…
ModificadaAlta (7.5)1.2%💥 ExploitFirestorm Technologies Gmaps1/8/200716/6/2026
SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.
ModificadaAlta (7.5)2.7%💥 ExploitNuralstorm Webmail18/10/200616/6/2026
PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DEFAULT_SKIN parameter.
Orbitaley — Vulnerabilidades