Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
512 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.6% | — | Linksalpha Social Sharing Toolkit Plugin | 25/10/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 0.99% | — | Google WEB Toolkit | 20/11/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue exists because of an incomplete fix for… | |
| Modificada | Media (4.3) | 0.97% | — | Google WEB Toolkit | 20/11/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 Beta and release candidates before 2.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.8) | 0.53% | — | Paypal WPS Toolkit | 6/11/2012 | 16/6/2026 | PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Alta (7.6) | 3.1% | — | Globus Toolkit | 7/6/2012 | 16/6/2026 | The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to gain privileges by logging in with a user that does not exist, which causes GridFTP to run as the last user in the… | |
| Modificada | Media (6.8) | 3.2% | — | Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+4 | 2/4/2012 | 16/6/2026 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit… | |
| Modificada | Media (6.8) | 3.2% | — | Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+4 | 2/4/2012 | 16/6/2026 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit… | |
| Modificada | Media (4.3) | 1.6% | — | Ncsa MyproxyGlobus Toolkit | 2/2/2011 | 16/6/2026 | MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a)… | |
| Modificada | Baja (2.1) | 0.38% | — | Nvidia Cuda Toolkit | 22/1/2011 | 16/6/2026 | The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations. | |
| Modificada | Media (5) | 1.2% | — | Dojofoundation Dojo ToolkitIBM Rational Clearquest | 29/12/2010 | 16/6/2026 | Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Adobe Extendedscript Toolkit CS5 | 27/8/2010 | 16/6/2026 | Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jsx file. | |
| Modificada | Alta (10) | 3.2% | — | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false options, which makes it easier for remote attackers to have an unspecified impact via a request to a… | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html. | |
| Modificada | Media (4.3) | 1.9% | — | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to… | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to dojo/resources/iframe_history.html,… | |
| Modificada | Alta (10) | 1.3% | — | Dojotoolkit Dojo | 15/6/2010 | 16/6/2026 | Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Webtoolkit WT | 6/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Emweb Wt before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to "insertions of the URL" that occur during a redirection. | |
| Modificada | Media (6.2) | 0.31% | — | HP Enterprise Cluster Master Toolkit | 3/2/2010 | 16/6/2026 | Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.11.31 (11i v3) allows local users to gain access to an Oracle or Sybase database via unknown vectors. | |
| Modificada | Alta (7.5) | 4.5% | — | Silcnet Silc ClientSilcnet Silc Toolkit | 10/9/2009 | 16/6/2026 | Multiple format string vulnerabilities in lib/silcclient/command.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client 1.1.8 and earlier, allow remote attackers to execute arbitrary code via format string specifiers in a channel name, related to (1) silc_client_command_topic, (2)… | |
| Modificada | Media (5.8) | 4.0% | — | Silcnet Silc Toolkit | 10/9/2009 | 16/6/2026 | The silc_http_server_parse function in lib/silchttp/silchttpserver.c in the internal HTTP server in silcd in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.9 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted Content-Length header, related to incorrect… | |
| Modificada | Media (5.8) | 3.4% | — | Silcnet Silc Toolkit | 10/9/2009 | 16/6/2026 | The silc_asn1_encoder function in lib/silcasn1/silcasn1_encode.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.8 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted OID value, related to incorrect use of a %lu format string. | |
| Modificada | Alta (7.5) | 4.8% | — | Silcnet Silc ClientSilcnet Silc Toolkit | 10/9/2009 | 16/6/2026 | Multiple format string vulnerabilities in lib/silcclient/client_entry.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client before 1.1.8, allow remote attackers to execute arbitrary code via format string specifiers in a nickname field, related to the (1) silc_client_add_client, (2)… | |
| Modificada | Media (4.3) | 1.1% | — | Dojotoolkit Dojo | 9/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dijit.Editor in Dojo before 1.1 allows remote attackers to inject arbitrary web script or HTML via XML entities in a TEXTAREA element. | |
| Modificada | Media (4.3) | 3.4% | — | Apache StrutsDojotoolkit Dojo | 9/4/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/. | |
| Rechazada | Sin puntuar | — | — | University OF Washington C-clientAIUniversity OF Washington Imap ToolkitAI | 22/2/2009 | 7/11/2023 | Rejected reason: Format string vulnerability in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit imap-2007d and other applications, allows remote attackers to execute arbitrary code via format string specifiers in the initial request to the IMAP port (143/tcp). NOTE: Red Hat has… |