Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.60% | — | ADD Link TO Facebook Project ADD Link TO Facebook | 4/1/2018 | 17/6/2026 | The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via the al2fb_facebook_id parameter to wp-admin/profile.php. | |
| Modificada | Alta (8.8) | 2.5% | 💥 Exploit | Facebook Clone Script Project Facebook Clone Script | 13/12/2017 | 17/6/2026 | Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Media (5.5) | 2.8% | — | Calibre-ebook Calibre | 16/3/2017 | 17/6/2026 | The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript. | |
| Modificada | Crítica (9.8) | 2.2% | — | Facebook Hhvm | 17/2/2017 | 17/6/2026 | Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Crítica (9.8) | 2.0% | — | Facebook Hhvm | 17/2/2017 | 17/6/2026 | The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to recursion. | |
| Modificada | Crítica (9.8) | 2.2% | — | Facebook Hhvm | 17/2/2017 | 17/6/2026 | Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Crítica (9.8) | 2.2% | — | Facebook Hhvm | 17/2/2017 | 17/6/2026 | Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Crítica (9.8) | 2.3% | — | Facebook Hhvm | 17/2/2017 | 17/6/2026 | Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a buffer overflow. | |
| Modificada | Crítica (9.8) | 2.2% | — | Facebook Hhvm | 17/2/2017 | 17/6/2026 | Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Media (6.1) | 1.0% | — | Phreesoft Phreebookserp | 15/2/2017 | 17/6/2026 | An issue was discovered in PhreeBooksERP before 2017-02-13. The vulnerability exists due to insufficient filtration of user-supplied data in the "form" HTTP GET parameter passed to the "PhreeBooksERP-master/extensions/ShippingMethods/ups/label_mgr/js_include.php" and… | |
| Modificada | Media (4.4) | 0.30% | — | Lenovo BiosLenovo Notebook 110 14ibr BiosLenovo Notebook 110 15ibr BiosLenovo Notebook B70 80 Bios+25 | 29/11/2016 | 17/6/2026 | A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system. | |
| Modificada | Alta (8.8) | 0.63% | — | Hiniarata Casebook Plugin | 6/4/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators. | |
| Modificada | Media (6.1) | 1.0% | — | Hiniarata Casebook Plugin | 6/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.63% | — | Hiniarata Casebook Plugin | 6/4/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators. | |
| Modificada | Media (6.1) | 1.0% | — | Hiniarata Casebook Plugin | 6/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.63% | — | Hiniarata Casebook Plugin | 6/4/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to hijack the authentication of administrators. | |
| Modificada | Media (6.1) | 1.0% | — | Hiniarata Casebook Plugin | 6/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.9) | 0.42% | — | HP 700 Series FirmwareHP 800 Series FirmwareHP Z240 FirmwareHP Z238 Firmware+3 | 4/3/2016 | 17/6/2026 | Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access. | |
| Modificada | Media (6.8) | 2.5% | — | Ipython NotebookJupyter Notebook | 29/9/2015 | 17/6/2026 | The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types. | |
| Modificada | Media (4.3) | 2.8% | — | Jupyter NotebookFedoraproject FedoraOpensuseIpython Notebook | 21/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF)… | |
| Modificada | Alta (7.8) | 7.1% | — | HP Hspa+ Gobi 4GHP Lt4112 LTEHP Elite X2 1010 G2HP Elitebook 1040 G1+35 | 27/8/2015 | 17/6/2026 | The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial of service, or execute arbitrary code, via unspecified vectors. | |
| Modificada | Media (6.9) | 0.51% | — | HP Hspa+ Gobi 4GHP Lt4112 LTEHP Elite X2 1010 G2HP Elitebook 1040 G1+35 | 27/8/2015 | 17/6/2026 | The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (4.3) | 2.7% | — | Nextendweb Facebook Connect | 24/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the new_fb_sign_button function in nextend-facebook-connect.php in Nextend Facebook Connect plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter. | |
| Modificada | Baja (3.5) | 0.95% | — | Facebook Album Fetcher Project Facebook Album Fetcher | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher module for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors. |