Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.71% | — | Gvectors Wpforo | 15/6/2020 | 17/6/2026 | The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter. | |
| Modificada | Alta (8.8) | 0.71% | — | Gvectors Wpforo | 15/6/2020 | 17/6/2026 | The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. | |
| Modificada | Baja (3.3) | 0.30% | — | Geovision Gv-gf192x Firmware | 12/6/2020 | 17/6/2026 | GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs. | |
| Modificada | Media (5.9) | 0.51% | — | Usavisionsys Geovision Gv-as210 FirmwareUsavisionsys Geovision Gv-as410 FirmwareUsavisionsys Geovision Gv-as810 FirmwareUsavisionsys Geovision Gv-as1010 Firmware+1 | 12/6/2020 | 17/6/2026 | GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages. | |
| Modificada | Crítica (9.8) | 0.87% | — | Usavisionsys Geovision Gv-as210 FirmwareUsavisionsys Geovision Gv-as410 FirmwareUsavisionsys Geovision Gv-as810 FirmwareUsavisionsys Geovision Gv-as1010 Firmware+1 | 12/6/2020 | 17/6/2026 | GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Honeywell H4d8pr1 FirmwareHoneywell Hfd5pr1 FirmwareHoneywell Hpw2p1 FirmwareHoneywell Hdzp304di Firmware+44 | 31/10/2019 | 17/6/2026 | Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP. | |
| Modificada | Crítica (9.8) | 1.4% | — | Honeywell H2w2pc1m FirmwareHoneywell H2w2per3 FirmwareHoneywell H2w4per3 FirmwareHoneywell H4w2per2 Firmware+60 | 31/10/2019 | 17/6/2026 | Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products. | |
| Modificada | Media (5.4) | 1.1% | — | Shapepress WP Dsgvo Tools | 29/8/2019 | 17/6/2026 | The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS. | |
| Modificada | Alta (7.5) | 1.9% | — | Androvideo VD 1 FirmwareGeovision Gv-vr360 FirmwareGeovision Gv-vd8700 Firmware | 29/8/2019 | 17/6/2026 | A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication. | |
| Modificada | Media (6.1) | 1.1% | — | Androvideo VD 1 FirmwareGeovision Gv-vr360 FirmwareGeovision Gv-vd8700 Firmware | 29/8/2019 | 17/6/2026 | A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly. | |
| Modificada | Crítica (9.8) | 1.9% | — | Androvideo VD 1 FirmwareGeovision Gv-vr360 FirmwareGeovision Gv-vd8700 Firmware | 29/8/2019 | 17/6/2026 | A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1 without any authentication. | |
| Modificada | Crítica (9.8) | 2.7% | — | Gvectors Wpforo Forum | 19/6/2019 | 17/6/2026 | An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction. | |
| Modificada | Alta (7.8) | 0.39% | — | Gnome Gvfs | 11/6/2019 | 17/6/2026 | daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a… | |
| Modificada | Media (5.7) | 1.8% | — | Gnome GvfsCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap | 29/5/2019 | 17/6/2026 | An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable. | |
| Modificada | Alta (8.1) | 1.8% | — | Gnome Gvfs | 29/5/2019 | 17/6/2026 | An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implement query_info_on_read/write. | |
| Modificada | Alta (7.3) | 1.8% | — | Gnome GvfsCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap | 29/5/2019 | 17/6/2026 | An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used. | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | Grandstream Gac2500 FirmwareGrandstream Gvc3202 FirmwareGrandstream Gxv3275 FirmwareGrandstream Gxv3240 Firmware+1 | 30/3/2019 | 17/6/2026 | Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie… | |
| Modificada | Alta (7) | 0.36% | — | Gnome Gvfs | 25/3/2019 | 17/6/2026 | An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users… | |
| Modificada | Media (5.5) | 0.28% | — | Google Gvisor | 17/12/2018 | 17/6/2026 | Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application. | |
| Modificada | Crítica (9.8) | 0.81% | — | Google Gvisor | 17/11/2018 | 17/6/2026 | pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in processes running as root (but not escape the sandbox) via vectors involving IPC_RMID shmctl calls, because reference counting is mishandled. | |
| Modificada | Media (6.8) | 0.45% | — | Google Gvisor | 2/9/2018 | 17/6/2026 | Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS. | |
| Modificada | Alta (7.5) | 0.99% | — | Genesis Vision Gvtoken | 4/7/2018 | 17/6/2026 | GVToken Genesis Vision (GVT) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner. | |
| Modificada | Alta (7.5) | 1.1% | — | GVE Globalvillage Ecosystem | 25/6/2018 | 17/6/2026 | The approveAndCallcode function of a smart contract implementation for Globalvillage ecosystem (GVE), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is not verified, aka the "evilReflex" issue.… | |
| Modificada | Media (6.1) | 3.6% | 💥 Exploit | Gvectors Wpforo Forum | 4/6/2018 | 17/6/2026 | wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI. |