Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | News Revolution - Bahrain Project News Revolution - Bahrain | 21/10/2014 | 17/6/2026 | The news revolution - bahrain (aka com.news.revolution.BH) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Snake Evolution Project Snake Evolution | 9/9/2014 | 17/6/2026 | The Snake Evolution (aka com.btwgames.snake) application 1.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.2% | — | Modx Revolution | 24/4/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) session ID (PHPSESSID) to index.php or remote authenticated users to execute arbitrary SQL commands via the (2) user parameter to connectors/security/message.php or (3) id… | |
| Modificada | Media (6.8) | 0.61% | — | B2evolution | 2/4/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945. | |
| Modificada | Media (6.5) | 2.8% | 💥 Exploit | B2evolution | 2/4/2014 | 16/6/2026 | SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands. | |
| Modificada | Alta (7.5) | 1.2% | — | Modx Revolution | 11/3/2014 | 17/6/2026 | SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Atcom Netvolution | 11/3/2014 | 17/6/2026 | SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Modx Revolution | 1/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in manager/templates/default/header.tpl in ModX Revolution before 2.2.11 allows remote attackers to inject arbitrary web script or HTML via the "a" parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Telligent Evolution | 27/2/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in controlpanel/loading.aspx in Telligent Evolution before 6.1.19.36103, 7.x before 7.1.12.36162, 7.5.x, and 7.6.x before 7.6.7.36651 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party… | |
| Modificada | Baja (3.3) | 0.35% | — | Debian Syncevolution | 28/1/2014 | 17/6/2026 | syncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite arbitrary files via a symlink attack on the new filename. | |
| Modificada | Media (4.3) | 2.7% | — | Oracle SolarisGnome EvolutionRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 8/3/2013 | 16/6/2026 | GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email. | |
| Modificada | Media (4.3) | 1.3% | — | B2evolution | 17/11/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body. | |
| Modificada | Media (6.5) | 1.1% | — | B2evolution | 17/11/2012 | 16/6/2026 | SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter. | |
| Modificada | Media (4.3) | 19% | 💥 Exploit | Modx Revolution | 7/10/2012 | 16/6/2026 | Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Atcom Netvolution | 21/10/2011 | 16/6/2026 | SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Atcom Netvolution | 21/10/2011 | 16/6/2026 | SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Atcom Netvolution | 21/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp in ATCOM Netvolution allows remote attackers to inject arbitrary web script or HTML via the query parameter in a Search action. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | Atcom Netvolution | 21/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Atcom Netvolution | 21/10/2011 | 16/6/2026 | SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter. | |
| Modificada | Baja (2.6) | 2.0% | 💥 Exploit | Modx Revolution | 7/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter. | |
| Modificada | Media (5) | 1.3% | — | B2evolution | 23/9/2011 | 16/6/2026 | b2evolution 3.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by locales/ru_RU/ru-RU.locale.php and certain other files. | |
| Modificada | Media (6.8) | 0.67% | — | Postrev Post Revolution | 6/6/2011 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests to (1) ajax-weblog-guardar.php, (2) verpost.php, (3) comments.php, or (4) perfil.php. | |
| Modificada | Media (4.3) | 1.1% | — | Postrev Post Revolution | 6/6/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in common.php in Post Revolution before 0.8.0c-2 allow remote attackers to inject arbitrary web script or HTML via an attribute of a (1) P, a (2) STRONG, a (3) A, a (4) EM, a (5) I, a (6) IMG, a (7) LI, an (8) OL, a (9) VIDEO, or a (10) BLOCKQUOTE element. | |
| Modificada | Media (5) | 1.5% | — | Postrev Post Revolution | 6/6/2011 | 16/6/2026 | common.php in Post Revolution before 0.8.0c-2 allows remote attackers to cause a denial of service (infinite loop) via malformed HTML markup, as demonstrated by an a< sequence. | |
| Modificada | Media (4.3) | 1.7% | — | Modxcms Evolution | 2/2/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image editor. |