Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
512 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+8 | 29/1/2019 | 17/6/2026 | In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials. | |
| Modificada | Alta (7.8) | 0.32% | — | Intel Openvino Toolkit | 12/9/2018 | 17/6/2026 | Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code using default directory permissions via local access. | |
| Modificada | Media (6.1) | 1.3% | — | Dojotoolkit Dojo | 6/9/2018 | 17/6/2026 | Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware,… | |
| Modificada | Crítica (9.8) | 2.5% | — | Dojotoolkit DojoDebian Linux | 18/8/2018 | 17/6/2026 | In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid. | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Activepdf Toolkit | 28/2/2018 | 17/6/2026 | The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images. | |
| Modificada | Media (6.1) | 1.2% | — | Dojotoolkit Dojo | 2/2/2018 | 17/6/2026 | dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element. | |
| Modificada | Media (5.9) | 1.2% | — | Percona ToolkitPercona Xtrabackup | 29/9/2017 | 17/6/2026 | The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional… | |
| Modificada | Alta (8.1) | 2.0% | — | Percona Toolkit | 29/9/2017 | 17/6/2026 | The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com. | |
| Modificada | Alta (7.5) | 1.8% | — | Metadata Anonymisation Toolkit Project Metadata Anonymisation Toolkit | 22/5/2017 | 17/6/2026 | Metadata Anonymisation Toolkit (MAT) 0.6 and 0.6.1 silently fails to perform "Clean metadata" actions upon invocation from the Nautilus contextual menu, which allows context-dependent attackers to obtain sensitive information by reading a file for which cleaning had been attempted. | |
| Modificada | Alta (7.8) | 2.3% | — | Foxitsoftware Foxit PDF Toolkit | 7/4/2017 | 17/6/2026 | Memory Corruption Vulnerability in Foxit PDF Toolkit before 2.1 allows an attacker to cause Denial of Service & Remote Code Execution when a victim opens a specially crafted PDF file. | |
| Modificada | Alta (7.8) | 2.3% | — | Foxitsoftware Foxit PDF Toolkit | 13/1/2017 | 17/6/2026 | Memory Corruption Vulnerability in Foxit PDF Toolkit v1.3 allows an attacker to cause Denial of Service and Remote Code Execution when the victim opens the specially crafted PDF file. The Vulnerability has been fixed in v2.0. | |
| Modificada | Media (4.3) | 0.34% | — | Citrix Xenmobile MDX ToolkitCitrix Worx Home | 13/7/2016 | 17/6/2026 | Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication. | |
| Modificada | Alta (7.5) | 3.6% | — | Adobe XMP Toolkit | 13/7/2016 | 17/6/2026 | XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (4.3) | 2.2% | — | Dojotoolkit Dojo | 11/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.1) | 1.1% | — | THE Extensible Catalog Drupal Toolkit Project THE Extensible Catalog Drupal Toolkit | 18/8/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "administer ncip providers" permission for requests that alter NCIP providers via a crafted request. | |
| Modificada | Media (6.4) | 1.9% | — | Devexpress Ajax Control Toolkit | 18/8/2015 | 17/6/2026 | Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd. | |
| Modificada | Media (5.4) | 0.27% | — | Designtoolkits Blocked IN Free | 20/10/2014 | 17/6/2026 | The Blocked in Free (aka com.blueup.blocked) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Etoolkit Love Collage - Photo Editor | 9/9/2014 | 17/6/2026 | The Love Collage - Photo Editor (aka com.etoolkit.lovecollage) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 1.0% | — | EMC RSA Bsafe ToolkitsEMC RSA Data Protection Manager | 17/6/2014 | 16/6/2026 | The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging unspecified… | |
| Modificada | Media (4.9) | 0.88% | — | Nongnu Oath Toolkit | 9/3/2014 | 17/6/2026 | usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated… | |
| Modificada | Media (5) | 3.6% | — | 3s-software Codesys Runtime Toolkit | 31/1/2014 | 17/6/2026 | Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors. | |
| Modificada | Media (4.3) | 4.6% | — | Microsoft Enhanced Mitigation Experience Toolkit | 29/11/2013 | 17/6/2026 | Microsoft Enhanced Mitigation Experience Toolkit (EMET) before 4.0 uses predictable addresses for hooked functions, which makes it easier for context-dependent attackers to defeat the ASLR protection mechanism via a return-oriented programming (ROP) attack. | |
| Modificada | Media (4.3) | 1.1% | — | Google WEB Toolkit | 18/11/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files in the GWTTestCase in Google Web Toolkit (GWT) before 2.5.1 RC1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.97% | — | Linksalpha Social Sharing Toolkit Plugin | 1/11/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors. | |
| Modificada | Media (6.8) | 10% | 💥 Exploit | KTH Snack Sound ToolkitKTH WavesurferOpensuse | 28/10/2013 | 16/6/2026 | Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file. |