Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
333 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.69% | — | Myperfectresume / Jobhero / Resume Clone Script Project Myperfectresume / Jobhero / Resume Clone Script | 9/8/2018 | 17/6/2026 | PHP Scripts Mall Myperfectresume / JobHero / Resume Clone Script 2.0.6 has Stored XSS via the Full Name and Title fields. | |
| Modificada | Alta (7.2) | 4.4% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (7.8) | 0.56% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Media (6.1) | 4.4% | 💥 Exploit | Hero-maps-pro Project Hero-maps-pro | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin hero-maps-pro v2.1.0 | |
| Modificada | Media (5.4) | 0.27% | — | AIR WAR Hero Project AIR WAR Hero | 19/10/2014 | 17/6/2026 | The Air War Hero (aka com.dev.airwar) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 3.2% | — | Gopro Hero FirmwareGopro Hero | 7/10/2014 | 17/6/2026 | gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action. | |
| Modificada | Alta (10) | 3.3% | — | Gopro Hero FirmwareGopro Hero | 7/10/2014 | 17/6/2026 | gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action. | |
| Modificada | Media (5.4) | 0.29% | — | Tradehero | 2/10/2014 | 17/6/2026 | The TradeHero (aka com.tradehero.th) application 2.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Superheroquiz Project Superheroquiz | 23/9/2014 | 17/6/2026 | The superheroquiz (aka com.davidhey.superheroquiz) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Likeheroapp Likehero GET Instagram Likes | 22/9/2014 | 17/6/2026 | The LikeHero Get Instagram Likes (aka com.fraoula.likehero) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Iqnect Dubstep Hero | 9/9/2014 | 17/6/2026 | The Dubstep Hero (aka com.electricpunch.dubstephero) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 2.8% | — | Fedoraproject FedoraMageia Project MageiaCherokee-project Cherokee | 2/7/2014 | 17/6/2026 | The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password. | |
| Modificada | Media (6.4) | 2.0% | — | HTC EVO 4G SoftwareHTC EVO 4GHTC EVO Design 4G SoftwareHTC EVO Design 4G+10 | 1/5/2012 | 16/6/2026 | The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send… | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | Infoproject Biznis Heroj | 30/12/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the config parameter to (1) nalozi_naslov.php and (2) widget.dokumenti_lista.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Infoproject Biznis Heroj | 30/12/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filter parameter to widget.dokumenti_lista.php, and (4) the fin_nalog_id parameter to nalozi_naslov.php. | |
| Modificada | Media (6.8) | 1.4% | — | Cherokee-project Cherokee | 7/10/2011 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, as demonstrated by a crafted nickname field to vserver/apply. | |
| Modificada | Baja (2.1) | 0.33% | — | Cherokee-project Cherokee | 7/10/2011 | 16/6/2026 | The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack. | |
| Modificada | Media (5) | 9.8% | 💥 Exploit | Cherokee-project Cherokee | 13/1/2010 | 16/6/2026 | header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5) | 4.1% | 💥 Exploit | Cherokee | 7/1/2010 | 16/6/2026 | Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word. | |
| Modificada | Media (5.5) | 1.1% | — | Netgear Wndap330 FirmwareAtheros Ar9160-bc1a Chipset | 12/11/2009 | 16/6/2026 | The Atheros wireless driver, as used in Netgear WNDAP330 Wi-Fi access point with firmware 2.1.11 and other versions before 3.0.3 on the Atheros AR9160-BC1A chipset, and other products, allows remote authenticated users to cause a denial of service (device reboot or hang) and possibly execute arbitrary code via a… | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Cherokee Httpd | 6/11/2009 | 16/6/2026 | Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL. | |
| Modificada | Alta (9.3) | 5.5% | 💥 Exploit | Heroshare Hero Super Player 3000 | 4/9/2009 | 16/6/2026 | Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | WEB Design Hero Joomladate | 10/2/2009 | 16/6/2026 | SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php. | |
| Modificada | Media (5) | 1.2% | — | Herongyang Hybook | 30/1/2009 | 16/6/2026 | hyBook Guestbook Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for hyBook.mdb. | |
| Modificada | Media (6.8) | 2.5% | — | Herosoft Hero DVD Player | 9/10/2008 | 16/6/2026 | Heap-based buffer overflow in Mplayer.exe in Herosoft Inc. Hero DVD Player 3.0.8 allows user-assisted remote attackers to execute arbitrary code via an M3u file with a "long entry." NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |