Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Servo Smallvec | 26/8/2019 | 17/6/2026 | An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity. | |
| Modificada | Crítica (9.8) | 1.8% | — | Servo Smallvec | 26/8/2019 | 17/6/2026 | An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors, leading to a double free. | |
| Modificada | Media (5.5) | 0.25% | — | Code42 FOR EnterpriseCode42 Crashplan FOR Small Business | 21/8/2019 | 17/6/2026 | In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write. | |
| Modificada | Alta (7) | 0.55% | — | Code42 FOR EnterpriseCode42 Crashplan FOR Small Business | 19/7/2019 | 17/6/2026 | Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user. | |
| Modificada | Media (4.3) | 2.2% | — | Kaspersky Anti-virusKaspersky Free Anti-virusKaspersky Internet SecurityKaspersky Small Office Security+1 | 18/7/2019 | 17/6/2026 | Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6 | |
| Modificada | Crítica (9.8) | 2.8% | — | Saet Tebe Small FirmwareSaet Webapp | 31/5/2019 | 17/6/2026 | The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to execute or include local .php files, as demonstrated by menu=php://filter/convert.base64-encode/resource=index.php to read index.php. | |
| Modificada | Alta (7.5) | 2.4% | — | Saet Tebe Small FirmwareSaet Webapp | 31/5/2019 | 17/6/2026 | The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password hashes via an inc/utils/REST_API.php?command=CallAPI&customurl=alladminusers call. | |
| Modificada | Alta (8) | 0.55% | — | Phpscriptsmall Online Food Ordering Script | 23/2/2019 | 17/6/2026 | PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php. | |
| Modificada | Media (4.8) | 0.51% | — | Dismall Discuz! | 22/11/2018 | 17/6/2026 | Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishandles statcode field from third-party stats code. | |
| Modificada | Alta (7.5) | 2.4% | — | Linlinjava Litemall | 17/10/2018 | 17/6/2026 | An issue was discovered in litemall 0.9.0. Arbitrary file download is possible via ../ directory traversal in linlinjava/litemall/wx/web/WxStorageController.java in the litemall-wx-api component. | |
| Modificada | Media (6.1) | 0.68% | — | Phpscriptsmall Website Seller Script | 4/10/2018 | 17/6/2026 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has XSS via the Listings Search feature. | |
| Modificada | Media (6.1) | 0.68% | — | Phpscriptsmall OLX Clone | 4/10/2018 | 17/6/2026 | PHP Scripts Mall Olx Clone 3.4.2 has XSS. | |
| Modificada | Media (5.3) | 1.9% | — | Marshmallow Project Marshmallow | 18/9/2018 | 17/6/2026 | In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and… | |
| Modificada | Alta (7.5) | 1.1% | — | Malltoken Project Malltoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for MallToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (8.8) | 0.52% | — | Wstmall | 29/6/2018 | 17/6/2026 | WSTMall v1.9.1_170316 has CSRF via the index.php?m=Admin&c=Users&a=edit URI to add a user account. | |
| Modificada | Media (6.1) | 0.68% | — | Dsmall Project Dsmall | 4/4/2018 | 17/6/2026 | dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html. | |
| Modificada | Media (5.4) | 0.54% | — | Dsmall Project Dsmall | 25/3/2018 | 17/6/2026 | dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI. | |
| Modificada | Media (6.1) | 0.68% | — | Dsmall Project Dsmall | 25/3/2018 | 17/6/2026 | dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI. | |
| Modificada | Media (5.4) | 0.54% | — | Dsmall Project Dsmall | 25/3/2018 | 17/6/2026 | dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box). | |
| Modificada | Alta (7.5) | 1.1% | — | Dsmall Project Dsmall | 25/3/2018 | 17/6/2026 | dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request. | |
| Modificada | Media (6.1) | 0.68% | — | Dsmall Project Dsmall | 22/3/2018 | 17/6/2026 | dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html. | |
| Modificada | Alta (7.7) | 1.6% | — | Cisco Small Business 500 Series Stackable Managed Switches Firmware | 8/3/2018 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device nay need to be… | |
| Modificada | Alta (7.5) | 1.9% | — | Sblim Project Small Footprint CIM Broker | 8/2/2018 | 17/6/2026 | SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI. | |
| Modificada | Alta (7.1) | 0.61% | — | Huawei Vmall | 22/11/2017 | 17/6/2026 | Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a malicious app which can send out HTTP requests and execute JavaScript code in web pages without obtaining the Internet access permission. Successful… | |
| Modificada | Baja (3.1) | 0.18% | — | Huawei Vmall | 22/11/2017 | 17/6/2026 | The upgrade package of Huawei Vmall APP Earlier than HwVmall 1.5.3.0 versions is transferred through HTTP. A man in the middle (MITM) can tamper with the upgrade package of Huawei Vmall APP, and to implant the malicious applications. |