Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.4% | — | Facebook Fizz | 29/4/2019 | 17/6/2026 | An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00. | |
| Modificada | Media (6.1) | 1.3% | — | Jupyter Notebook | 4/4/2019 | 17/6/2026 | In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255. | |
| Modificada | Media (6.1) | 1.8% | — | JupyterhubJupyter Notebook | 28/3/2019 | 17/6/2026 | An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected. | |
| Modificada | Media (5.4) | 1.5% | — | Jupyter Notebook | 12/3/2019 | 17/6/2026 | An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though… | |
| Modificada | Crítica (9.8) | 1.7% | — | Facebook Hhvm | 15/1/2019 | 17/6/2026 | The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return… | |
| Modificada | Media (5.9) | 1.1% | — | Facebook Wangle | 15/1/2019 | 17/6/2026 | Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connections. This affects versions of Wangle prior to v2019.01.14.00 | |
| Modificada | Crítica (9.8) | 1.7% | — | Facebook Hhvm | 15/1/2019 | 17/6/2026 | The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implementation of the function will cause a string to be created with an invalid length, which can then interact poorly with other functions. This affects all supported versions… | |
| Modificada | Crítica (9.8) | 2.3% | — | Facebook Nuclide | 31/12/2018 | 17/6/2026 | The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide… | |
| Modificada | Crítica (9.8) | 2.5% | — | Facebook Buck | 31/12/2018 | 17/6/2026 | Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06.25.01. | |
| Modificada | Alta (7.5) | 0.83% | — | Facebook Proxygen | 31/12/2018 | 17/6/2026 | Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00. | |
| Modificada | Crítica (9.8) | 2.8% | — | Facebook React-dev-utils | 31/12/2018 | 17/6/2026 | react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the server (either via CSRF or by direct request) to execute… | |
| Modificada | Media (6.1) | 3.4% | 💥 PoC | Facebook React | 31/12/2018 | 17/6/2026 | React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2,… | |
| Modificada | Alta (8.1) | 1.4% | — | Facebook Hhvm | 31/12/2018 | 17/6/2026 | The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below). | |
| Modificada | Alta (7.5) | 1.8% | — | Facebook FollyFacebook Hhvm | 31/12/2018 | 17/6/2026 | folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00. | |
| Modificada | Alta (7.5) | 1.5% | — | Facebook Hhvm | 31/12/2018 | 17/6/2026 | A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests. | |
| Modificada | Crítica (9.8) | 1.9% | — | Facebook Hhvm | 31/12/2018 | 17/6/2026 | Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below). | |
| Modificada | Media (5.9) | 1.1% | — | Facebook Hhvm | 3/12/2018 | 17/6/2026 | A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate resources. This affects all supported versions of HHVM (3.24.3 and 3.21.7 and below) when using the proxygen server to handle HTTP2 requests. | |
| Modificada | Media (6.1) | 1.3% | — | Jupyter Notebook | 18/11/2018 | 17/6/2026 | Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely. | |
| Modificada | Media (6.1) | 1.5% | — | Jupyter Notebook | 18/11/2018 | 17/6/2026 | Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and… | |
| Modificada | Media (4.6) | 1.1% | 💥 PoC | HP 240 G1 FirmwareHP 245 G1 FirmwareHP 1000-1300 FirmwareHP 250 G1 Notebook PC Firmware+30 | 3/10/2018 | 17/6/2026 | A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014. | |
| Modificada | Media (6.1) | 1.0% | — | Webdados Open Graph FOR Facebook, Google+ AND Twitter Card Tags | 14/5/2018 | 17/6/2026 | Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.1% | — | Jupyter Notebook | 18/3/2018 | 17/6/2026 | In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous. | |
| Modificada | Alta (7.8) | 4.5% | — | Calibre-ebook Calibre | 8/3/2018 | 17/6/2026 | gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call. | |
| Modificada | Media (5.4) | 0.55% | — | Facebook Clone Script Project Facebook Clone Script | 12/2/2018 | 17/6/2026 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Vastal I-tech Buddy Zone Facebook Clone | 29/1/2018 | 17/6/2026 | SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category parameter. |