Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.4%—Facebook Fizz29/4/201917/6/2026
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.
ModificadaMedia (6.1)1.3%—Jupyter Notebook4/4/201917/6/2026
In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.
ModificadaMedia (6.1)1.8%—JupyterhubJupyter Notebook28/3/201917/6/2026
An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.
ModificadaMedia (5.4)1.5%—Jupyter Notebook12/3/201917/6/2026
An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though…
ModificadaCrítica (9.8)1.7%—Facebook Hhvm15/1/201917/6/2026
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return…
ModificadaMedia (5.9)1.1%—Facebook Wangle15/1/201917/6/2026
Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connections. This affects versions of Wangle prior to v2019.01.14.00
ModificadaCrítica (9.8)1.7%—Facebook Hhvm15/1/201917/6/2026
The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implementation of the function will cause a string to be created with an invalid length, which can then interact poorly with other functions. This affects all supported versions…
ModificadaCrítica (9.8)2.3%—Facebook Nuclide31/12/201817/6/2026
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide…
ModificadaCrítica (9.8)2.5%—Facebook Buck31/12/201817/6/2026
Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06.25.01.
ModificadaAlta (7.5)0.83%—Facebook Proxygen31/12/201817/6/2026
Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.
ModificadaCrítica (9.8)2.8%—Facebook React-dev-utils31/12/201817/6/2026
react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the server (either via CSRF or by direct request) to execute…
ModificadaMedia (6.1)3.4%💥 PoCFacebook React31/12/201817/6/2026
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2,…
ModificadaAlta (8.1)1.4%—Facebook Hhvm31/12/201817/6/2026
The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
ModificadaAlta (7.5)1.8%—Facebook FollyFacebook Hhvm31/12/201817/6/2026
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00.
ModificadaAlta (7.5)1.5%—Facebook Hhvm31/12/201817/6/2026
A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests.
ModificadaCrítica (9.8)1.9%—Facebook Hhvm31/12/201817/6/2026
Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below).
ModificadaMedia (5.9)1.1%—Facebook Hhvm3/12/201817/6/2026
A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate resources. This affects all supported versions of HHVM (3.24.3 and 3.21.7 and below) when using the proxygen server to handle HTTP2 requests.
ModificadaMedia (6.1)1.3%—Jupyter Notebook18/11/201817/6/2026
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
ModificadaMedia (6.1)1.5%—Jupyter Notebook18/11/201817/6/2026
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and…
ModificadaMedia (4.6)1.1%💥 PoCHP 240 G1 FirmwareHP 245 G1 FirmwareHP 1000-1300 FirmwareHP 250 G1 Notebook PC Firmware+303/10/201817/6/2026
A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.
ModificadaMedia (6.1)1.0%—Webdados Open Graph FOR Facebook, Google+ AND Twitter Card Tags14/5/201817/6/2026
Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)1.1%—Jupyter Notebook18/3/201817/6/2026
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
ModificadaAlta (7.8)4.5%—Calibre-ebook Calibre8/3/201817/6/2026
gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.
ModificadaMedia (5.4)0.55%—Facebook Clone Script Project Facebook Clone Script12/2/201817/6/2026
Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script.
ModificadaCrítica (9.8)3.0%💥 ExploitVastal I-tech Buddy Zone Facebook Clone29/1/201817/6/2026
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category parameter.