Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.60%—ADD Link TO Facebook Project ADD Link TO Facebook4/1/201817/6/2026
The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via the al2fb_facebook_id parameter to wp-admin/profile.php.
ModificadaAlta (8.8)2.5%💥 ExploitFacebook Clone Script Project Facebook Clone Script13/12/201717/6/2026
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaMedia (5.5)2.8%—Calibre-ebook Calibre16/3/201717/6/2026
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.
ModificadaCrítica (9.8)2.2%—Facebook Hhvm17/2/201717/6/2026
Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
ModificadaCrítica (9.8)2.0%—Facebook Hhvm17/2/201717/6/2026
The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to recursion.
ModificadaCrítica (9.8)2.2%—Facebook Hhvm17/2/201717/6/2026
Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
ModificadaCrítica (9.8)2.2%—Facebook Hhvm17/2/201717/6/2026
Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
ModificadaCrítica (9.8)2.3%—Facebook Hhvm17/2/201717/6/2026
Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a buffer overflow.
ModificadaCrítica (9.8)2.2%—Facebook Hhvm17/2/201717/6/2026
Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
ModificadaMedia (6.1)1.0%—Phreesoft Phreebookserp15/2/201717/6/2026
An issue was discovered in PhreeBooksERP before 2017-02-13. The vulnerability exists due to insufficient filtration of user-supplied data in the "form" HTTP GET parameter passed to the "PhreeBooksERP-master/extensions/ShippingMethods/ups/label_mgr/js_include.php" and…
ModificadaMedia (4.4)0.30%—Lenovo BiosLenovo Notebook 110 14ibr BiosLenovo Notebook 110 15ibr BiosLenovo Notebook B70 80 Bios+2529/11/201617/6/2026
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.
ModificadaAlta (8.8)0.63%—Hiniarata Casebook Plugin6/4/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.
ModificadaMedia (6.1)1.0%—Hiniarata Casebook Plugin6/4/201617/6/2026
Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)0.63%—Hiniarata Casebook Plugin6/4/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.
ModificadaMedia (6.1)1.0%—Hiniarata Casebook Plugin6/4/201617/6/2026
Cross-site scripting (XSS) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)0.63%—Hiniarata Casebook Plugin6/4/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to hijack the authentication of administrators.
ModificadaMedia (6.1)1.0%—Hiniarata Casebook Plugin6/4/201617/6/2026
Cross-site scripting (XSS) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.9)0.42%—HP 700 Series FirmwareHP 800 Series FirmwareHP Z240 FirmwareHP Z238 Firmware+34/3/201617/6/2026
Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.
ModificadaMedia (6.8)2.5%—Ipython NotebookJupyter Notebook29/9/201517/6/2026
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
ModificadaMedia (4.3)2.8%—Jupyter NotebookFedoraproject FedoraOpensuseIpython Notebook21/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF)…
ModificadaAlta (7.8)7.1%—HP Hspa+ Gobi 4GHP Lt4112 LTEHP Elite X2 1010 G2HP Elitebook 1040 G1+3527/8/201517/6/2026
The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial of service, or execute arbitrary code, via unspecified vectors.
ModificadaMedia (6.9)0.51%—HP Hspa+ Gobi 4GHP Lt4112 LTEHP Elite X2 1010 G2HP Elitebook 1040 G1+3527/8/201517/6/2026
The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vectors.
ModificadaMedia (4.3)2.7%—Nextendweb Facebook Connect24/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the new_fb_sign_button function in nextend-facebook-connect.php in Nextend Facebook Connect plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter.
ModificadaBaja (3.5)0.95%—Facebook Album Fetcher Project Facebook Album Fetcher21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher module for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.
Orbitaley — Vulnerabilidades