Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)17%💥 ExploitAdobe Photoshop CCAdobe Bridge24/6/201517/6/2026
Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (10)5.1%—Adobe Photoshop CC24/6/201517/6/2026
Adobe Photoshop CC before 16.0 (aka 2015.0.0) allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
ModificadaMedia (5)2.1%—Toshiba Chec24/6/201517/6/2026
CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.
ModificadaAlta (7.5)1.5%—Audiosharescript Audioshare23/6/201517/6/2026
PHP remote file inclusion vulnerability in ajax/myajaxphp.php in AudioShare 2.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the config['basedir'] parameter.
ModificadaMedia (4.3)1.0%—Audiosharescript Audioshare23/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in forgot.php in AudioShare 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
ModificadaMedia (6.8)0.64%—Joshics Contact Form Fields21/4/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Contact Form Fields module before 6.x-2.3 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete fields via unspecified vectors.
ModificadaMedia (6.9)0.38%—Toshiba Bluetooth StackToshiba Service Station28/2/201517/6/2026
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
ModificadaMedia (4.3)1.5%—Cosmoshop27/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter).
ModificadaMedia (6.8)0.61%—Zaunz Gmbh Cosmoshop1/1/201516/6/2026
Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/setup_edit.cgi in CosmoShop ePRO 10.05.00 allows remote attackers to hijack the authentication of administrators for requests that modify settings via a setup action.
ModificadaMedia (4.3)0.97%—Zaunz Gmbh Cosmoshop1/1/201516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in CosmoShop ePRO 10.05.00 allow remote attackers to inject arbitrary web script or HTML via (1) the rcopy parameter to cgi-bin/admin/rubrikadmin.cgi, (2) the typ parameter to cgi-bin/admin/artikeladmin.cgi, or (3) the suchbegriff parameter to…
ModificadaMedia (4.3)1.6%—Swipe HQ Checkout FOR Jigoshop2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for Jigoshop (swipe-hq-checkout-for-jigoshop) plugin 3.1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.
ModificadaAlta (9.3)23%💥 ExploitAdobe Photoshop CS5Adobe Photoshop Cs5.119/6/201416/6/2026
Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a long Collada asset element in a DAE file, as demonstrated by the cameraYFov value in the contributor comments element.
ModificadaMedia (6.8)1.1%—Kieranoshea Calendar27/5/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in the Calendar plugin before 1.3.3 for WordPress allows remote attackers to hijack the authentication of users for requests that add a calendar entry via unspecified vectors.
ModificadaBaja (3)0.28%—Toshibacommerce 4690 Point OF Sale Operating System21/4/201417/6/2026
The default configuration of IBM 4690 OS, as used in Toshiba Global Commerce Solutions 4690 POS and other products, hashes passwords with the ADXCRYPT algorithm, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified cryptanalysis of an ADXCSOUF.DAT file.
ModificadaMedia (6.8)1.1%💥 ExploitToshibatec E-studio-232Toshibatec E-studio-233Toshibatec E-studio-282Toshibatec E-studio-28319/4/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords.
ModificadaMedia (5)1.3%—Posh Project Posh1/4/201417/6/2026
The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie.
ModificadaMedia (4.3)2.2%—Joshua Peek Rack-ssl25/3/201417/6/2026
Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack.
ModificadaAlta (7.5)2.4%💥 ExploitPosh Project Posh3/3/201417/6/2026
SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the rssurl parameter.
ModificadaAlta (7.5)1.3%—Etoshop Classifieds Creator24/12/201317/6/2026
Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.
ModificadaAlta (7.5)2.5%💥 ExploitEtoshop C2C Forward Auction Creator21/12/201317/6/2026
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to auction/casp/admin.asp.
ModificadaAlta (7.5)2.3%💥 ExploitEtoshop Dynamic BIZ Website Builder Quickweb21/12/201317/6/2026
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp.
ModificadaAlta (10)9.0%—Adobe Photoshop Cs5.5Adobe Photoshop CS64/9/201216/6/2026
Heap-based buffer overflow in Photoshop.exe in Adobe Photoshop CS5 12.x before 12.0.5, CS5.1 12.1.x before 12.1.1, and CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted TIFF image with SGI24LogLum compression.
ModificadaAlta (9.3)11%💥 ExploitAdobe Photoshop CS631/8/201216/6/2026
Buffer overflow in Adobe Photoshop CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted file.
ModificadaMedia (5)1.6%—Moshe Weitzman Organic Groups14/8/201216/6/2026
The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private group titles via a request through the Views module.
ModificadaMedia (4)11%💥 ExploitKeith Winstein Mosh29/6/201216/6/2026
The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.