Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.6% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 9/6/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163. | |
| Modificada | Alta (7.8) | 0.89% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 9/6/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1170. | |
| Modificada | Media (5.3) | 15% | 💥 PoC | Divante Storefront-apiDivante Vue-storefront-api | 17/4/2020 | 17/6/2026 | In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names. | |
| Modificada | Alta (7.1) | 0.71% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 15/4/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'. | |
| Modificada | Media (6.1) | 0.81% | — | Mediawiki Mobilefrontend | 19/3/2020 | 17/6/2026 | In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL1_33. | |
| Modificada | Crítica (9.8) | 2.9% | — | Netvu Dv-ip Express FirmwareNetvu Sd-advanced - Sdhd FirmwareNetvu Sd-advanced 8/12/16 VGA FirmwareNetvu SD Advanced Closed Iptv (m3u) Firmware+16 | 6/2/2020 | 17/6/2026 | Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The… | |
| Modificada | Crítica (9.8) | 2.8% | — | Advancedcustomfields ACF Fronted Display | 10/10/2019 | 17/6/2026 | The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php. | |
| Modificada | Alta (7.5) | 4.1% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 23/9/2019 | 17/6/2026 | A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'. | |
| Modificada | Media (6.5) | 1.0% | — | Epignosishq Efront LMS | 5/9/2019 | 17/6/2026 | An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compromise. An attacker can use a browser to trigger these vulnerabilities, and no special tools are… | |
| Modificada | Alta (8.8) | 2.3% | — | Epignosishq Efront LMS | 5/9/2019 | 17/6/2026 | A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability. | |
| Analizada | Alta (7.5) | 30% | ⚠ Explotación activa💥 Exploit | Citrix Storefront Server | 29/8/2019 | 17/6/2026 | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks. | |
| Modificada | Crítica (9.8) | 2.1% | — | WP Front END Profile Project WP Front END Profile | 21/8/2019 | 17/6/2026 | The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue. | |
| Modificada | Media (6.1) | 0.91% | — | WP Front END Profile Project WP Front END Profile | 21/8/2019 | 17/6/2026 | The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS. | |
| Modificada | Alta (7.1) | 0.95% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 14/8/2019 | 17/6/2026 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete… | |
| Modificada | Media (6.1) | 0.70% | — | Mediawiki Mobilefrontend | 9/8/2019 | 17/6/2026 | In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Media (6.1) | 1.0% | — | Vfront | 3/6/2019 | 17/6/2026 | VFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php azzera parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Vfront | 3/6/2019 | 17/6/2026 | VFront 0.99.5 has stored XSS via the admin/sync_reg_tab.php azzera parameter, which is mishandled during admin/error_log.php rendering. | |
| Modificada | Media (6.5) | 1.5% | — | Kofax Front Office Server | 18/4/2019 | 17/6/2026 | An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP file) within the Kofax/KFS/Admin/PackageService/package/upload file parameter. | |
| Modificada | Media (5.4) | 0.63% | — | Kofax Front Office Server | 18/4/2019 | 17/6/2026 | Kofax Front Office Server version 4.1.1.11.0.5212 (both Thin Client and Administration Console) suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Filename" field in /Kofax/KFS/ThinClient/document/upload/ - (Thin Client) or (2) "DeviceName" field in /Kofax/KFS/Admin/DeviceService/device/ -… | |
| Modificada | Media (4.9) | 0.43% | — | Kofax Front Office Server | 18/4/2019 | 17/6/2026 | In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, as demonstrated by an mfp.password downloadsettingvalue operation. | |
| Modificada | Crítica (9.8) | 1.5% | — | Frontaccounting | 8/1/2019 | 17/6/2026 | includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via the void_transaction.php filterType parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Frontaccounting | 28/12/2018 | 17/6/2026 | FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application. | |
| Modificada | Crítica (9.8) | 30% | — | Microsoft Forefront Unified Access Gateway | 5/7/2018 | 17/6/2026 | uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome. | |
| Modificada | Alta (7.5) | 2.0% | — | Node-server-forfront Project Node-server-forfront | 7/6/2018 | 17/6/2026 | node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |