Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2) | 0.52% | — | Abcd-community Abcd | 4/9/2024 | 17/6/2026 | A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument Sub_Expresion can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (5.3) | 0.69% | — | Abcd-community Abcd | 4/9/2024 | 17/6/2026 | A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/php/otros_sitios.php. The manipulation of the argument sitio leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.65% | — | Abcd-community Abcd | 4/9/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_image.php. The manipulation of the argument image leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 1.3% | — | C-first Cfr-1004ea FirmwareC-first Cfr-1008ea FirmwareC-first Cfr-1016ea FirmwareC-first Cfr-16eaa Firmware+24 | 16/11/2023 | 17/6/2026 | Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and… | |
| Modificada | Crítica (9.8) | 1.1% | — | C-first Cfr-1004ea FirmwareC-first Cfr-1008ea FirmwareC-first Cfr-1016ea FirmwareC-first Cfr-16eaa Firmware+24 | 16/11/2023 | 17/6/2026 | First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other… | |
| Modificada | Alta (8.8) | 2.5% | — | Agilebio Labcollector | 12/6/2023 | 17/6/2026 | LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent. | |
| Modificada | Crítica (9.8) | 0.95% | — | Collabcal Project Collabcal | 7/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in holdennb CollabCal. Affected is the function handleGet of the file calenderServer.cpp. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The patch is identified as b80f6d1893607c99e5113967592417d0fe310ce6. It… | |
| Modificada | Media (4.6) | 0.25% | — | Samsung T-oscpakuc FirmwareSamsung T-oscpdeuc FirmwareSamsung T-oscpuabc FirmwareSamsung T-nkm2akuc Firmware+11 | 13/12/2022 | 17/6/2026 | The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 models, xxxA1000, 4x2A0200 for 2022 models. | |
| Modificada | Media (6.5) | 1.7% | — | Abcm2ps Project Abcm2psFedoraproject FedoraDebian Linux | 10/3/2022 | 17/6/2026 | An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors. | |
| Modificada | Media (5.5) | 1.3% | — | Abcm2ps Project Abcm2psFedoraproject FedoraDebian Linux | 10/3/2022 | 17/6/2026 | Stack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors. | |
| Modificada | Media (5.5) | 0.98% | — | Abcm2ps Project Abcm2psFedoraproject FedoraDebian Linux | 10/3/2022 | 17/6/2026 | abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c. | |
| Modificada | Baja (3.1) | 0.68% | — | Labcup | 10/6/2021 | 17/6/2026 | In LabCup before <v2_next_18022, it is possible to use the save API to perform unauthorized actions for users without access to user management in order to, after successful exploitation, gain access to a victim's account. A user without the user-management privilege can change another user's email address if the… | |
| Modificada | Crítica (9.8) | 2.6% | — | Abcprintf Upload-image-with-ajax | 23/12/2019 | 17/6/2026 | Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution. | |
| Modificada | Media (5.5) | 0.92% | — | Moinejf Abcm2psDebian Linux | 18/7/2019 | 17/6/2026 | moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to cause a denial of service attack via a crafted file. The component is: front.c, function txt_add. The fixed version is: after commit commit 08aef597656d065e86075f3d53fda89765845eae. | |
| Modificada | Alta (7.5) | 2.0% | — | Serverabc Project Serverabc | 7/6/2018 | 17/6/2026 | serverabc is a static file server. serverabc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Crítica (9.8) | 3.1% | — | Moinejf Abcm2psDebian LinuxFedoraproject Fedora | 7/5/2018 | 17/6/2026 | Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. | |
| Modificada | Crítica (9.8) | 2.7% | — | Moinejf Abcm2psDebian LinuxFedoraproject Fedora | 5/5/2018 | 17/6/2026 | Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. | |
| Modificada | Media (5.4) | 0.27% | — | Tabtale ABC Song | 30/9/2014 | 17/6/2026 | The ABC Song (aka com.tabtale.abcsingalong) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc ABC Lounge Webradio | 25/9/2014 | 17/6/2026 | The ABC Lounge Webradio (aka com.nobexinc.wls_66087017.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 2.2% | — | Invensys DasabcipInvensys Daserver Runtime ComponentsInvensys DassidirectInvensys Intouch/wonderware Application Server+1 | 5/7/2012 | 16/6/2026 | Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and… | |
| Modificada | Alta (10) | 2.6% | — | Moinejf Abcm2psFedoraproject Fedora | 18/2/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441. | |
| Modificada | Media (6.8) | 3.2% | — | Moinejf Abcm2psFedoraproject Fedora | 18/2/2011 | 16/6/2026 | Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 5.9% | — | Moinejf Abcm2psFedoraproject Fedora | 18/2/2011 | 16/6/2026 | Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input file, related to the trim_title function; and possibly (3) a long -O option on a command line. | |
| Modificada | Alta (9.3) | 5.3% | — | Abcbackup ABC BackupInternet-soft Urgent Backup | 5/5/2010 | 16/6/2026 | Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP archive. | |
| Modificada | Alta (7.5) | 1.0% | — | Airiny COM ABC | 3/5/2010 | 16/6/2026 | SQL injection vulnerability in the Airiny ABC (com_abc) component 1.1.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sectionid parameter in an abc action to index.php. |