Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Amazon Clone Project Amazon Clone | 13/12/2017 | 17/6/2026 | FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari. | |
| Modificada | Alta (7.8) | 1.6% | — | Amazon Audible | 6/12/2017 | 17/6/2026 | ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched from a directory where an attacker has already created a Trojan horse dwmapi.dll file. | |
| Modificada | Media (6.5) | 2.2% | — | Amazon KEY Firmware | 16/11/2017 | 17/6/2026 | Amazon Key through 2017-11-16 mishandles Cloud Cam 802.11 deauthentication frames during the delivery process, which makes it easier for (1) delivery drivers to freeze a camera and re-enter a house for unfilmed activities or (2) attackers to freeze a camera and enter a house if a delivery driver failed to ensure a… | |
| Modificada | Alta (7.8) | 0.40% | — | Amazon WEB Services Cloudformation Bootstrap | 30/10/2017 | 17/6/2026 | The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary code with root privileges by leveraging the ability to create files in an unspecified directory. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | 2kblater 2KB Amazon Affiliates Store | 28/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php. | |
| Modificada | Crítica (9.8) | 1.9% | — | Amazon Fire OS | 10/4/2017 | 17/6/2026 | Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackers to cause a denial of service (panic) or possibly have unspecified other impact via a long string to /dev/hv. | |
| Modificada | Alta (7.3) | 1.2% | — | Amazon Kindle FOR PC | 15/3/2017 | 17/6/2026 | Untrusted search path vulnerability in Amazon Kindle for PC before 1.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL in the current working directory of the Kindle Setup installer. | |
| Modificada | Media (6.5) | 1.0% | — | Amazonbasics FirmwareDell Km714 FirmwareDell Km632 FirmwareLogitech Unifying Firmware+1 | 2/8/2016 | 17/6/2026 | The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity… | |
| Modificada | Media (5) | 2.1% | — | Amazon AWS Project Amazon AWS | 21/4/2015 | 17/6/2026 | The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL. | |
| Modificada | Media (5) | 2.4% | — | ZendrestZend FrameworkZendservice SlideshareZendservice API+6 | 16/11/2014 | 17/6/2026 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before… | |
| Modificada | Media (6.8) | 2.2% | — | ZendrestZend FrameworkZendservice SlideshareZendservice API+6 | 16/11/2014 | 17/6/2026 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before… | |
| Modificada | Media (6.4) | 2.6% | — | ZendrestZend FrameworkZendservice SlideshareZendservice API+6 | 16/11/2014 | 17/6/2026 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before… | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Websupporter WP Amasin - THE Amazon Affiliate Shop | 21/10/2014 | 17/6/2026 | Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Daily Free APP @ Amazon Project Daily Free APP @ Amazon | 18/9/2014 | 17/6/2026 | The Daily Free App @ Amazon (aka com.kattanweb.android.dfaa) application 1.5.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 0.52% | — | Amazon Kindle | 30/8/2014 | 17/6/2026 | The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.0% | — | Wp-tmkm-amazon Project Wp-tmkm-amazon | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in wp-tmkm-amazon-search.php in the wp-tmkm-amazon plugin 1.5b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the AID parameter. | |
| Modificada | Alta (7.4) | 0.78% | — | Amazon EC2 API Tools Java LibraryCodehaus Xfire | 4/11/2012 | 16/6/2026 | Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an… | |
| Modificada | Media (5.8) | 0.57% | — | Amazon Flexible Payments Service | 4/11/2012 | 16/6/2026 | Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to… | |
| Modificada | Media (5.8) | 0.73% | — | Amazon Elastic Load Balancing | 4/11/2012 | 16/6/2026 | Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default… | |
| Modificada | Media (5.8) | 0.57% | — | Amazon Merchant SDK | 4/11/2012 | 16/6/2026 | The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (6.9) | 0.40% | — | Amazon Kindle FOR PC | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Amazon Kindle for PC 1.3.0 30884 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .azw file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 3.7% | — | Amazon Kindle Touch | 12/8/2012 | 16/6/2026 | The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a string, as demonstrated by using lipc-set-prop to set an LIPC property, a different vulnerability than CVE-2012-4248. | |
| Modificada | Alta (9.3) | 3.5% | — | Amazon Kindle Touch | 12/8/2012 | 16/6/2026 | The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote attackers to have an unspecified impact via vectors involving the (1) dev.log, (2) lipc.set, (3) lipc.get, or (4) todo.scheduleItems method, a different vulnerability than… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Phpbb Amazonia MOD | 15/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 7/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976. |