Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Browsercrm | 25/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Browsercrm | 25/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login[username] parameter to index.php, (2) parent_id parameter to modules/Documents/version_list.php, or (3) contact_id parameter to modules/Documents/index.php. | |
| Modificada | Media (4.3) | 1.2% | — | JB+ Jigbrowser+ | 28/9/2012 | 16/6/2026 | The jigbrowser+ application before 1.5.0 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application. | |
| Modificada | Alta (9.3) | 4.3% | — | Caminova Djvu Browser Plug-in | 19/9/2012 | 16/6/2026 | Heap-based buffer overflow in npdjvu.dll in Caminova DjVu Browser Plug-in 6.1.4 Build 27351 and other versions before 6.1.4.27993 allows remote attackers to execute arbitrary code via a crafted Sjbz chunk in a djvu file. | |
| Modificada | Media (4.3) | 1.2% | — | Cybozu Kunai Browser FOR Remote Service | 14/9/2012 | 16/6/2026 | The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL. | |
| Modificada | Media (6.9) | 0.42% | — | Maxthon Browser | 7/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan horse (1) RSRC32.dll or (2) dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .html file. NOTE: the provenance of this information is… | |
| Modificada | Media (5) | 1.3% | — | Opera Browser | 30/8/2012 | 16/6/2026 | Opera before 11.60 allows remote attackers to spoof the address bar via unspecified homograph characters, a different vulnerability than CVE-2010-2660. | |
| Modificada | Media (4.3) | 1.5% | — | Opera Browser | 6/8/2012 | 16/6/2026 | Opera before 12.01 allows remote attackers to cause a denial of service (application crash) via a crafted web site, as demonstrated by the Lenovo "Shop now" page. | |
| Modificada | Alta (10) | 2.2% | — | Opera Browser | 6/8/2012 | 16/6/2026 | Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue." | |
| Modificada | Media (4.3) | 1.2% | — | Opera Browser | 6/8/2012 | 16/6/2026 | Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted HTML document. | |
| Modificada | Media (6.8) | 1.3% | — | Opera Browser | 6/8/2012 | 16/6/2026 | Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog, a different vulnerability than CVE-2012-1924. | |
| Modificada | Media (4.3) | 1.2% | — | Opera Browser | 6/8/2012 | 16/6/2026 | Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, ignores some characters in HTML documents in unspecified circumstances, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document. | |
| Modificada | Media (4.3) | 1.2% | — | Yahoo! Browser | 16/7/2012 | 16/6/2026 | The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application. | |
| Modificada | Media (6.8) | 1.2% | — | Browserid Project Browserid | 27/6/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that login a user to another web site. | |
| Modificada | Media (4.3) | 1.1% | — | Dolphin-browser Dolphin Browser HDDolphin-browser Dolphin FOR PAD | 15/6/2012 | 16/6/2026 | The Dolphin Browser HD application before 7.6 and Dolphin for Pad application before 1.0.1 for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application. | |
| Modificada | Media (5) | 0.96% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via crafted WebGL content, as demonstrated by a codeflow.org WebGL demo. | |
| Modificada | Media (5) | 1.2% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Opera before 12.00 Beta allows remote attackers to cause a denial of service (memory consumption or application hang) via an IFRAME element that uses the src="#" syntax to embed a parent document. | |
| Modificada | Media (4.3) | 1.1% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Opera before 12.00 Beta allows user-assisted remote attackers to cause a denial of service (application hang) via JavaScript code that changes a form before submission. | |
| Modificada | Media (5) | 1.2% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via crafted characters in domain names, as demonstrated by "IDNA2008 tests." | |
| Modificada | Media (5) | 1.2% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Opera before 12.00 Beta allows remote attackers to cause a denial of service (application hang) via an absolutely positioned wrap=off TEXTAREA element located next to an "overflow: auto" block element. | |
| Modificada | Media (5) | 1.2% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via a web page that contains invalid character encodings. | |
| Modificada | Media (4.3) | 0.84% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Opera before 12.00 Beta allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page that is not properly handled during a reload, as demonstrated by a "multiple origin camera test" page. | |
| Modificada | Alta (10) | 5.2% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Opera before 11.64 does not properly allocate memory for URL strings, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted string. | |
| Modificada | Media (4.3) | 2.0% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Opera before 11.65 does not ensure that the address field corresponds to the displayed web page during blocked navigation, which makes it easier for remote attackers to conduct spoofing attacks by detecting and preventing attempts to load a different web page. | |
| Modificada | Alta (10) | 1.4% | — | Opera Browser | 14/6/2012 | 16/6/2026 | Unspecified vulnerability in Opera before 12.00 on Mac OS X has unknown impact and attack vectors, related to a "moderate severity issue." |