Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
313 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.3% | — | Sandstorm | 6/2/2018 | 17/6/2026 | Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip function doesn't filter Line Feed (\n) characters in a directory name. | |
| Modificada | Crítica (9.8) | 3.0% | — | Sandstorm | 6/2/2018 | 17/6/2026 | A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field. | |
| Modificada | Media (6.5) | 1.4% | — | Sandstorm | 6/2/2018 | 17/6/2026 | The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to cause a denial of service by launching a fork bomb in the sandbox, or by using a large amount of disk space. | |
| Modificada | Alta (7.5) | 5.3% | — | Apache Storm | 30/10/2017 | 17/6/2026 | Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log. | |
| Modificada | Alta (8.8) | 4.9% | — | Apache Storm | 9/8/2017 | 17/6/2026 | It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other… | |
| Modificada | Crítica (9.8) | 14% | — | Apache Storm | 13/1/2017 | 17/6/2026 | The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Sunstormgames Donut Maker | 9/9/2014 | 17/6/2026 | The Donut Maker (aka com.sunstorm.android.donut) application 1.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.8% | — | Breakingpointsystems Breakingpoint Storm Appliance CTMBreakingpointsystems Breakingpoint Storm Appliance | 12/8/2012 | 16/6/2026 | The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents. | |
| Modificada | Media (5) | 1.8% | — | Breakingpointsystems Breakingpoint Storm Appliance CTMBreakingpointsystems Breakingpoint Storm Appliance | 12/8/2012 | 16/6/2026 | The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive information by downloading a .tgz file. | |
| Modificada | Alta (10) | 1.7% | — | Ucweb Ucmobile Blovestorm | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in the UCMobile BloveStorm (com.blovestorm) application 2.2.0 and 3.2.1 for Android has unknown impact and attack vectors. | |
| Modificada | Baja (2.1) | 0.66% | — | Speedtech Storm | 7/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) phone, or (3) im parameter in a stormperson action to index.php. NOTE: the… | |
| Modificada | Baja (2.1) | 1.5% | — | Speedtech Storm | 1/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) address, (3) city, (4) provstate (aka state), (5) phone, or (6) taxid… | |
| Modificada | Alta (7.5) | 1.0% | — | Typo3 Brainstorming | 19/3/2010 | 16/6/2026 | SQL injection vulnerability in the Brainstorming extension 0.1.8 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 1.3% | — | Speedtech Storm | 31/12/2009 | 16/6/2026 | The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecified vectors. | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Baofeng Storm | 27/7/2009 | 16/6/2026 | Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist file. | |
| Modificada | Alta (9.3) | 7.5% | 💥 Exploit | Baofeng Storm | 28/5/2009 | 16/6/2026 | Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009. | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Baofeng Storm | 11/5/2009 | 16/6/2026 | Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (6) | 0.85% | — | Drupal Storm | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Stormboards Aaronnemisis Stormboards | 26/12/2008 | 16/6/2026 | SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Guliverkli Media Player ClassicMympc Cd-stormVerycd Stormplayer | 18/9/2007 | 16/6/2026 | Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi… | |
| Modificada | Alta (9.3) | 3.3% | — | Baofeng Storm | 18/9/2007 | 16/6/2026 | Multiple buffer overflows in a certain ActiveX control in sparser.dll in Baofeng Storm 2.8 and earlier allow remote attackers to execute arbitrary code via malformed input in an unknown set of arguments or property values, a different DLL than CVE-2007-4816. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Alta (9.3) | 4.4% | — | Guliverkli Media Player ClassicMympc Cd-stormVerycd Stormplayer | 18/9/2007 | 16/6/2026 | Multiple integer overflows in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain… | |
| Modificada | Alta (7.5) | 9.2% | 💥 Exploit | Baofeng Storm | 11/9/2007 | 16/6/2026 | Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a long first argument to the advancedOpen method; a long argument to the (5) isDVDPath or (6) rawParse method; or (7) a… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Firestorm Technologies Gmaps | 1/8/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Nuralstorm Webmail | 18/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DEFAULT_SKIN parameter. |