Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.6% | — | Codfront Labs Http Strict Transport Security | 18/8/2015 | 17/6/2026 | The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown… | |
| Modificada | Alta (7.5) | 2.2% | — | Frontend User Upload Project Frontend User Upload | 16/6/2015 | 17/6/2026 | Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension using a frontend form, then accessing it via a direct request to the file in the fileadmin folder. | |
| Modificada | Media (6.8) | 0.78% | — | Epignosis Efront | 10/2/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in administrator.php in Epignosis eFront Open Source Edition before 3.6.15.3 build 18022 allow remote attackers to hijack the authentication of administrators for requests that (1) delete modules via the delete_module parameter, (2) deactivate modules via the… | |
| Modificada | Media (4.3) | 6.5% | 💥 Exploit | Frontend Uploader Project Frontend Uploader | 2/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI. | |
| Modificada | Media (5.4) | 0.27% | — | Pocketmags Front | 20/10/2014 | 17/6/2026 | The FRONT (aka com.magazinecloner.front) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Core-apps Digital Content Newfronts 2014 | 19/10/2014 | 17/6/2026 | The Digital Content NewFronts 2014 (aka com.coreapps.android.followme.newfronts2014) application 6.0.7.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.7% | — | CWT Frontend Edit Project CWT Frontend Edit | 11/9/2014 | 17/6/2026 | Unspecified vulnerability in the CWT Frontend Edit (cwt_feedit) extension before 1.2.5 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Americostech Selfshot Front Flash Camera | 9/9/2014 | 17/6/2026 | The Selfshot - Front Flash Camera (aka com.americos.selfshot) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Efrontlearning Efront | 11/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via the surname parameter to student.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Frontaccounting | 5/6/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.3.21 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.94% | — | Mediafront | 20/5/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings. | |
| Modificada | Alta (10) | 21% | — | Microsoft Forefront Protection 2010 | 12/2/2014 | 17/6/2026 | Microsoft Forefront Protection 2010 for Exchange Server does not properly parse e-mail content, which might allow remote attackers to execute arbitrary code via a crafted message, aka "RCE Vulnerability." | |
| Modificada | Baja (3.5) | 2.6% | 💥 Exploit | Efrontlearning Efront | 21/12/2013 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Last name, (2) Lesson name, or (3) Course name field. | |
| Modificada | Media (4.3) | 30% | — | Microsoft Frontpage | 11/9/2013 | 16/6/2026 | Microsoft FrontPage 2003 SP3 does not properly parse DTDs, which allows remote attackers to obtain sensitive information via crafted XML data in a FrontPage document, aka "XML Disclosure Vulnerability." | |
| Modificada | Media (5) | 1.5% | — | Efrontlearning Efront | 24/1/2013 | 16/6/2026 | eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, which reveals the installation path in an error message. | |
| Modificada | Media (4.3) | 1.7% | — | Mediafront | 28/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the "stand alone PHP application for the OSM Player," as used in the MediaFront module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal, allow remote attackers to inject arbitrary web script or HTML via (1) $_SERVER['HTTP_HOST'] or (2)… | |
| Modificada | Baja (3.5) | 0.97% | — | Efrontlearning Efront | 13/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the subject box of a message. | |
| Modificada | Media (6) | 2.1% | — | Efrontlearning Efront | 13/8/2012 | 16/6/2026 | Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachment in a message. | |
| Modificada | Media (6.9) | 0.40% | — | Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+3 | 27/4/2012 | 16/6/2026 | Untrusted search path vulnerability in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, and oreplug allows local users to gain privileges via a Trojan… | |
| Modificada | Alta (9.3) | 4.2% | — | Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+7 | 27/4/2012 | 16/6/2026 | Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro4, Shuriken 2007 through 2010, Shuriken Pro4 Corporate Edition,… | |
| Modificada | Media (5) | 36% | — | Microsoft Forefront Unified Access Gateway | 10/4/2012 | 16/6/2026 | Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability." | |
| Modificada | Media (5.8) | 11% | — | Microsoft Forefront Unified Access Gateway | 10/4/2012 | 16/6/2026 | Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability." | |
| Analizada | Media (4.3) | 3.7% | 💥 Exploit | Arcinfo FrontvueArcinfo PcvueArcinfo Plantvue | 3/4/2012 | 9/7/2026 | Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document. | |
| Analizada | Media (5.8) | 27% | 💥 Exploit | Arcinfo FrontvueArcinfo PcvueArcinfo Plantvue | 3/4/2012 | 9/7/2026 | An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods. | |
| Analizada | Alta (9.3) | 7.4% | 💥 Exploit | Arcinfo FrontvueArcinfo PcvueArcinfo Plantvue | 3/4/2012 | 9/7/2026 | Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer overflow. |