Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.45% | — | Accountsservice Project AccountsserviceOpensuseDebian LinuxRedhat Enterprise Linux | 27/11/2019 | 16/6/2026 | An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Attach Accounts TO Orders | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (5.4) | 0.58% | — | Nchsoftware Express Accounts Accounting | 17/10/2019 | 17/6/2026 | In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Orders/Items/Customers/Quotes fields parameter to inject arbitrary JavaScript. | |
| Modificada | Media (6.5) | 3.0% | — | Freedesktop Accountsservice | 13/7/2018 | 17/6/2026 | Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c. | |
| Modificada | Baja (3.6) | 0.38% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 16/4/2014 | 16/6/2026 | The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Gnome Online AccountsCanonical Ubuntu Linux | 2/4/2013 | 16/6/2026 | Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue… | |
| Modificada | Media (4.3) | 1.4% | — | Gnome Online AccountsCanonical Ubuntu Linux | 2/4/2013 | 16/6/2026 | Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. | |
| Modificada | Baja (1.9) | 0.36% | — | RAY Stode Accountsservice | 22/7/2012 | 16/6/2026 | The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition. | |
| Modificada | Alta (7.8) | 2.8% | 💥 Exploit | PHP Accounts | 22/6/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local files via unspecified manipulations of the page parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | PHP Accounts | 22/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in PHPAccounts 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) Outgoing_Type_ID, (2) Outgoing_ID, (3) Project_ID, (4) Client_ID, (5) Invoice_ID, or (6) Vendor_ID parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Horde Accounts | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title. |