Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.6%—Chartered Accountant \ Auditor Website Project21/3/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field.
ModificadaMedia (5.4)0.65%—Chartered Accountant \ Auditor Website Project21/3/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.
ModificadaAlta (8.8)0.51%—Chartered Accountant \ Auditor Website Project10/8/201817/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.
ModificadaMedia (6.1)1.0%—Chartered Accountant \ Auditor Website Project9/7/201817/6/2026
PHP Scripts Mall Auditor Website 2.0.1 has XSS via the lastname or firstname parameter.
ModificadaAlta (7.8)16%💥 ExploitDevicelock Plug AND Play Auditor10/5/201817/6/2026
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
ModificadaAlta (7.5)7.0%—OpenldapOpensuse LeapOracle Blockchain PlatformMcafee Policy Auditor18/12/201717/6/2026
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.
ModificadaCrítica (9.8)3.0%💥 ExploitCMS Auditor Website Project CMS Auditor Website13/12/201717/6/2026
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
ModificadaMedia (6.5)7.2%—OpenldapDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+629/5/201717/6/2026
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
ModificadaAlta (7.5)12%💥 ExploitSecure-bytes Secure Cisco Auditor21/5/201717/6/2026
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.
ModificadaAlta (8.1)12%—Libexpat Project LibexpatCanonical Ubuntu LinuxMcafee Policy AuditorPython30/6/201617/6/2026
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
ModificadaCrítica (9.8)13%—Mozilla FirefoxApple MAC OS XSuse Linux Enterprise DebuginfoSuse Studio Onsite+1026/5/201617/6/2026
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
ModificadaMedia (4.3)1.3%—Stefan Auditor Vcard26/10/200916/6/2026
Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the addition of the theme_vcard function to a theme and the use of default content.
Orbitaley — Vulnerabilidades