Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.6% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field. | |
| Modificada | Media (5.4) | 0.65% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field. | |
| Modificada | Alta (8.8) | 0.51% | — | Chartered Accountant \ Auditor Website Project | 10/8/2018 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php. | |
| Modificada | Media (6.1) | 1.0% | — | Chartered Accountant \ Auditor Website Project | 9/7/2018 | 17/6/2026 | PHP Scripts Mall Auditor Website 2.0.1 has XSS via the lastname or firstname parameter. | |
| Modificada | Alta (7.8) | 16% | 💥 Exploit | Devicelock Plug AND Play Auditor | 10/5/2018 | 17/6/2026 | DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH). | |
| Modificada | Alta (7.5) | 7.0% | — | OpenldapOpensuse LeapOracle Blockchain PlatformMcafee Policy Auditor | 18/12/2017 | 17/6/2026 | contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | CMS Auditor Website Project CMS Auditor Website | 13/12/2017 | 17/6/2026 | CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail. | |
| Modificada | Media (6.5) | 7.2% | — | OpenldapDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+6 | 29/5/2017 | 17/6/2026 | servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Secure-bytes Secure Cisco Auditor | 21/5/2017 | 17/6/2026 | Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname. | |
| Modificada | Alta (8.1) | 12% | — | Libexpat Project LibexpatCanonical Ubuntu LinuxMcafee Policy AuditorPython | 30/6/2016 | 17/6/2026 | The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716. | |
| Modificada | Crítica (9.8) | 13% | — | Mozilla FirefoxApple MAC OS XSuse Linux Enterprise DebuginfoSuse Studio Onsite+10 | 26/5/2016 | 17/6/2026 | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. | |
| Modificada | Media (4.3) | 1.3% | — | Stefan Auditor Vcard | 26/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the addition of the theme_vcard function to a theme and the use of default content. |