Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 0.68% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 12/1/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.67% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 9/12/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.88% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 24/11/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | GBU Grafici COM Gbufacebook | 23/11/2011 | 16/6/2026 | SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_face action to index.php. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1296. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1229. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1228. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1227. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1226. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1225. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1222. | |
| Modificada | Alta (10) | 0.89% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 12/9/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.125 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.91% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 12/9/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Dmxready Online Notebook Manager | 21/6/2010 | 16/6/2026 | SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Todd Rogers Phprecipebook | 11/6/2010 | 16/6/2026 | SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL commands via the (1) base_id or (2) course_id parameter in a search action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Commodityrentals Books/ebooks Rentals Script | 2/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gamecatalog action. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Witchakorn Kamolpornwijit COM Facebook | 28/9/2009 | 16/6/2026 | SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Platinumprofitzone Turnkey Ebook Store | 2/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action. | |
| Modificada | Media (4.3) | 0.84% | — | Andrew Freed Quotebook | 5/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in QuoteBook allows remote attackers to inject arbitrary web script or HTML via the (1) QuoteName and (2) QuoteText parameters to quotesadd.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Andrew Freed Quotebook | 5/3/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText parameters to (b) quotesadd.php. NOTE: the provenance of this information is unknown; the details… | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Freedville Quotebook | 5/3/2009 | 16/6/2026 | QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request. | |
| Modificada | Media (4.4) | 0.28% | — | Alcovebook Sgml2x | 4/3/2009 | 16/6/2026 | rlatex in AlcoveBook sgml2x 1.0.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 1.2% | — | Dmxready Online Notebook Manager | 10/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in DMXReady Online Notebook Manager 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. NOTE: some third parties report inability to verify this issue. | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Facebook Photouploader | 24/12/2008 | 16/6/2026 | Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Common-solutions Csphonebook | 4/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter. |