Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.0% | — | Synology Surveillance Station | 27/2/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTML via the userDesc parameter. | |
| Modificada | Alta (8.8) | 0.59% | — | Limesurvey | 9/2/2018 | 17/6/2026 | LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable. This attack appear to be exploitable via Simple HTML markup can be used to send a GET… | |
| Modificada | Crítica (9.8) | 3.6% | — | Surveys Project Surveys | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query. | |
| Modificada | Crítica (9.8) | 3.6% | — | Surveys Project Surveys | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query. | |
| Modificada | Crítica (9.8) | 3.6% | — | Surveys Project Surveys | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query. | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | Nuuo Nvrmini 2Netgear Readynas Surveillance | 31/8/2016 | 17/6/2026 | Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn parameter to the transfer_license command. | |
| Modificada | Alta (8.8) | 14% | 💥 Exploit | Nuuo Nvrmini 2Netgear Readynas Surveillance | 31/8/2016 | 17/6/2026 | cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_license command. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Netgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo | 31/8/2016 | 17/6/2026 | NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request. | |
| Modificada | Alta (7.5) | 54% | 💥 Exploit | Netgear Readynas SurveillanceNuuo NvrsoloNuuo Nvrmini 2 | 31/8/2016 | 17/6/2026 | cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action. | |
| Modificada | Crítica (9.8) | 71% | 💥 Exploit | Netgear Readynas SurveillanceNuuo CrystalNuuo NvrsoloNuuo Nvrmini 2 | 31/8/2016 | 17/6/2026 | handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter. | |
| Modificada | Crítica (9.8) | 95% | 💥 Exploit | Netgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo | 31/8/2016 | 17/6/2026 | __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter. | |
| Modificada | Media (6.5) | 1.6% | — | Limesurvey | 28/6/2015 | 17/6/2026 | SQL injection vulnerability in the insert function in application/controllers/admin/dataentry.php in LimeSurvey 2.06+ allows remote authenticated users to execute arbitrary SQL commands via the closedate parameter. | |
| Modificada | Media (6.5) | 1.6% | — | Limesurvey | 18/6/2015 | 17/6/2026 | SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter. | |
| Modificada | Alta (7.5) | 4.7% | 💥 Exploit | Sympies Wordpress Survey AND Poll | 26/2/2015 | 17/6/2026 | SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php. | |
| Modificada | Media (6.5) | 1.7% | 💥 Exploit | Classapps Selectsurvey.net | 6/11/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to execute arbitrary SQL commands via the SurveyID parameter to survey/ReviewReadOnlySurvey.aspx or (2) remote authenticated users to execute arbitrary SQL commands via the SurveyID parameter to… | |
| Modificada | Media (5.4) | 0.27% | — | Harvestyourdata Droid Survey Offline Forms | 20/10/2014 | 17/6/2026 | The droid Survey Offline Forms (aka com.contact.droidSURVEY) application 2.5.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Survey.com Mobile | 22/9/2014 | 17/6/2026 | The Survey.com Mobile (aka com.survey.android) application 3.2.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.5% | — | Limesurvey | 21/7/2014 | 17/6/2026 | Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume. | |
| Modificada | Alta (7.5) | 1.9% | — | Limesurvey | 21/7/2014 | 17/6/2026 | SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Limesurvey | 21/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to… | |
| Modificada | Media (4.3) | 2.2% | — | Cisco Video Surveillance Indoor Fixed Dome IP HD Camera | 25/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950. | |
| Modificada | Media (6.8) | 1.6% | — | Cisco Video Surveillance Operations Manager | 24/1/2014 | 17/6/2026 | Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from a client system with a crafted host name, aka Bug ID… | |
| Modificada | Media (6.4) | 1.2% | — | Cisco Video Surveillance 4000 IP CameraCisco Video Surveillance 4300e IP CameraCisco Video Surveillance 4500e IP Camera | 16/10/2013 | 16/6/2026 | The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419. | |
| Modificada | Media (5) | 1.3% | — | Cisco Video Surveillance Operations Manager | 30/9/2013 | 16/6/2026 | The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262. | |
| Modificada | Alta (10) | 8.5% | — | HP Identity Driven ManagerHP Procurve Manager | 16/9/2013 | 16/6/2026 | The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows remote attackers to execute arbitrary commands via a HEAD request, aka ZDI-CAN-1745. |