Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 17% | 💥 Exploit | Adobe Photoshop CCAdobe Bridge | 24/6/2015 | 17/6/2026 | Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 5.1% | — | Adobe Photoshop CC | 24/6/2015 | 17/6/2026 | Adobe Photoshop CC before 16.0 (aka 2015.0.0) allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | Toshiba Chec | 24/6/2015 | 17/6/2026 | CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access. | |
| Modificada | Alta (7.5) | 1.5% | — | Audiosharescript Audioshare | 23/6/2015 | 17/6/2026 | PHP remote file inclusion vulnerability in ajax/myajaxphp.php in AudioShare 2.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the config['basedir'] parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Audiosharescript Audioshare | 23/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in forgot.php in AudioShare 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the email parameter. | |
| Modificada | Media (6.8) | 0.64% | — | Joshics Contact Form Fields | 21/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Contact Form Fields module before 6.x-2.3 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete fields via unspecified vectors. | |
| Modificada | Media (6.9) | 0.38% | — | Toshiba Bluetooth StackToshiba Service Station | 28/2/2015 | 17/6/2026 | Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character. | |
| Modificada | Media (4.3) | 1.5% | — | Cosmoshop | 27/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter). | |
| Modificada | Media (6.8) | 0.61% | — | Zaunz Gmbh Cosmoshop | 1/1/2015 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/setup_edit.cgi in CosmoShop ePRO 10.05.00 allows remote attackers to hijack the authentication of administrators for requests that modify settings via a setup action. | |
| Modificada | Media (4.3) | 0.97% | — | Zaunz Gmbh Cosmoshop | 1/1/2015 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CosmoShop ePRO 10.05.00 allow remote attackers to inject arbitrary web script or HTML via (1) the rcopy parameter to cgi-bin/admin/rubrikadmin.cgi, (2) the typ parameter to cgi-bin/admin/artikeladmin.cgi, or (3) the suchbegriff parameter to… | |
| Modificada | Media (4.3) | 1.6% | — | Swipe HQ Checkout FOR Jigoshop | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for Jigoshop (swipe-hq-checkout-for-jigoshop) plugin 3.1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter. | |
| Modificada | Alta (9.3) | 23% | 💥 Exploit | Adobe Photoshop CS5Adobe Photoshop Cs5.1 | 19/6/2014 | 16/6/2026 | Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a long Collada asset element in a DAE file, as demonstrated by the cameraYFov value in the contributor comments element. | |
| Modificada | Media (6.8) | 1.1% | — | Kieranoshea Calendar | 27/5/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Calendar plugin before 1.3.3 for WordPress allows remote attackers to hijack the authentication of users for requests that add a calendar entry via unspecified vectors. | |
| Modificada | Baja (3) | 0.28% | — | Toshibacommerce 4690 Point OF Sale Operating System | 21/4/2014 | 17/6/2026 | The default configuration of IBM 4690 OS, as used in Toshiba Global Commerce Solutions 4690 POS and other products, hashes passwords with the ADXCRYPT algorithm, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified cryptanalysis of an ADXCSOUF.DAT file. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Toshibatec E-studio-232Toshibatec E-studio-233Toshibatec E-studio-282Toshibatec E-studio-283 | 19/4/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords. | |
| Modificada | Media (5) | 1.3% | — | Posh Project Posh | 1/4/2014 | 17/6/2026 | The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie. | |
| Modificada | Media (4.3) | 2.2% | — | Joshua Peek Rack-ssl | 25/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Posh Project Posh | 3/3/2014 | 17/6/2026 | SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the rssurl parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Etoshop Classifieds Creator | 24/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Etoshop C2C Forward Auction Creator | 21/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to auction/casp/admin.asp. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Etoshop Dynamic BIZ Website Builder Quickweb | 21/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp. | |
| Modificada | Alta (10) | 9.0% | — | Adobe Photoshop Cs5.5Adobe Photoshop CS6 | 4/9/2012 | 16/6/2026 | Heap-based buffer overflow in Photoshop.exe in Adobe Photoshop CS5 12.x before 12.0.5, CS5.1 12.1.x before 12.1.1, and CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted TIFF image with SGI24LogLum compression. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Adobe Photoshop CS6 | 31/8/2012 | 16/6/2026 | Buffer overflow in Adobe Photoshop CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (5) | 1.6% | — | Moshe Weitzman Organic Groups | 14/8/2012 | 16/6/2026 | The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private group titles via a request through the Views module. | |
| Modificada | Media (4) | 11% | 💥 Exploit | Keith Winstein Mosh | 29/6/2012 | 16/6/2026 | The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value. |