Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.1% | — | Facebook Hiphop Virtual Machine | 13/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddx_serialize_value function. | |
| Modificada | Media (4.3) | 1.7% | — | Web-dorado Spider Facebook | 11/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Spider Facebook plugin before 1.0.11 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the appid parameter in a registration task to the default URI or remote administrators to inject arbitrary web script or HTML via the (2)… | |
| Modificada | Media (6.8) | 1.2% | — | Facebook Like BOX Project Facebook Like BOX | 5/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Facebook Like Box (cardoza-facebook-like-box) plugin before 2.8.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting… | |
| Modificada | Media (5) | 1.7% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key string uses '\0' for termination, which allows remote attackers to obtain sensitive information by leveraging read access beyond the end of the string, and makes it… | |
| Modificada | Alta (7.5) | 1.9% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted arguments to the chunk_split function. | |
| Modificada | Media (5) | 1.5% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initialization vector. | |
| Modificada | Media (5) | 2.1% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypass intended access restrictions by leveraging group permissions for a file or directory. | |
| Modificada | Alta (7.5) | 2.7% | — | Facebook Hiphop Virtual Machine | 28/12/2014 | 17/6/2026 | CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Nextendweb Nextend Facebook Connect | 5/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fb_login_button parameter in a newfb_update_options action. | |
| Modificada | Media (5.4) | 0.27% | — | Androidebookapp Healthy Lunch Diet Recipes | 19/10/2014 | 17/6/2026 | The Healthy Lunch Diet Recipes (aka com.best.lunchdietrecipes) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Facebook Profits ON Steroids Project Facebook Profits ON Steroids | 19/10/2014 | 17/6/2026 | The Facebook Profits on Steroids (aka com.wFacebookProfitsonSteroids) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Sigong Ebook Project Sigong Ebook | 19/10/2014 | 17/6/2026 | The Sigong ebook (aka com.sigongsa.sigonggenre) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Praninc Facebook Facts | 22/9/2014 | 17/6/2026 | The Facebook Facts (aka com.wFacebookFacts) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Statusvia Facebook Status VIA | 18/9/2014 | 17/6/2026 | The Facebook Status Via (aka com.StatusViaAdvanced) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 0.94% | — | FacebookFacebook Messenger | 15/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Facebook app 14.0 and the Facebook Messenger app 10.0 for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted filename extension that is improperly handled during MIME sniffing of chat traffic. NOTE: the vendor disputes the significance of… | |
| Modificada | Media (5.4) | 0.27% | — | Free Ebooks Project Free Ebooks | 9/9/2014 | 17/6/2026 | The Free eBooks (aka com.bmfapps.freekindlebooks) application 14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 4.7% | — | OpensuseIpython NotebookMageia | 7/8/2014 | 17/6/2026 | IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page. | |
| Modificada | Media (6.8) | 1.2% | — | Madeofcode Omniauth-facebook | 13/5/2014 | 16/6/2026 | The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter. | |
| Modificada | Media (6.8) | 0.97% | — | Crunchify Facebook Members | 5/5/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify this plugin's settings. | |
| Modificada | Media (4.3) | 1.2% | — | Clonemonster Social Book Facebook Clone Monster | 20/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Social Book Facebook Clone 2010 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) signup.php, (2) lostpass.php, (3) login.php, (4) index.php, (5) help_tos.php, (6) help_contact.php, or (7) help.php. | |
| Modificada | Alta (10) | 0.69% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Chromebox 3+2 | 7/6/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Series 5, 5 550, and Chromebox 3; and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Phpgradebook PHP Grade Book | 31/3/2012 | 16/6/2026 | admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action. | |
| Modificada | Alta (10) | 0.68% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 29/2/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Bluechip BC Post2facebook | 14/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Manfred Egger BC Post2facebook | 14/2/2012 | 16/6/2026 | SQL injection vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |