Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1306▼ 184 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4)0.99%—IBM Lotus Notes Traveler16/12/201016/6/2026
IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread.
ModificadaMedia (5.8)1.1%—IBM Lotus Notes Traveler16/12/201016/6/2026
The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes ID file, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
ModificadaAlta (7.5)15%💥 ExploitPeter Hocherl COM Travelbook26/4/201016/6/2026
Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)1.1%—Dietmar Schffer Travelmate19/3/201016/6/2026
SQL injection vulnerability in the Meet Travelmates (travelmate) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaBaja (2.1)0.33%—Kingston Datatraveler BlackboxKingston Datatraveler EliteKingston Datatraveler Secure7/1/201016/6/2026
Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data…
ModificadaMedia (4.6)0.36%—Kingston Datatraveler BlackboxKingston Datatraveler EliteKingston Datatraveler Secure7/1/201016/6/2026
Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining…
ModificadaBaja (2.1)0.48%—Kingston Datatraveler BlackboxKingston Datatraveler EliteKingston Datatraveler Secure7/1/201016/6/2026
Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive…
ModificadaAlta (7.5)2.3%💥 ExploitLeinir Travelsized CMS13/3/200816/6/2026
Multiple directory traversal vulnerabilities in index.php in Travelsized CMS 0.4.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page_id and (2) language parameters. NOTE: this might be the same issue as CVE-2008-1325.
ModificadaAlta (7.5)6.8%💥 ExploitTime-travellers Oftpd16/1/200716/6/2026
oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address family, which triggers an assertion failure.
ModificadaAlta (7.5)1.1%💥 ExploitLotfian Request FOR Travel14/12/200616/6/2026
SQL injection vulnerability in ProductDetails.asp in Lotfian Request For Travel 1.0 allows remote attackers to execute arbitrary SQL commands via the PID parameter.
ModificadaMedia (6.8)1.7%—Leinir Travelsized CMS22/11/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dan Jensen Travelsized CMS 0.4.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) page, (2) page_id, or (3) language parameter.
ModificadaAlta (7.5)2.8%💥 ExploitDAN Jensen Travelsized CMS10/10/200616/6/2026
PHP remote file inclusion vulnerability in frontpage.php in Dan Jensen Travelsized CMS 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.