Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.4% | — | Elvedia Flashcanvas | 22/11/2019 | 17/6/2026 | Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header. | |
| Modificada | Alta (7.8) | 1.5% | — | Canvasgfx Canvas Draw | 6/2/2019 | 17/6/2026 | An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code… | |
| Modificada | Alta (7.8) | 1.8% | — | Canvasgfx Canvas Draw | 6/2/2019 | 17/6/2026 | An exploitable out-of-bounds write exists in the CALS Raster file format-parsing functionality of Canvas Draw version 5.0.0.28. A specially crafted CAL image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a CAL image to trigger this vulnerability… | |
| Modificada | Alta (7.8) | 1.9% | — | Canvasgfx Canvas Draw | 6/2/2019 | 17/6/2026 | An exploitable out of bounds write exists in the CAL parsing functionality of Canvas Draw version 5.0.0. A specially crafted CAL image processed via the application can lead to an out of bounds write overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution. | |
| Modificada | Media (5.9) | 1.1% | — | Coolpad Canvas Firmware | 28/12/2018 | 17/6/2026 | The Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform app with a package name of com.qualcomm.qti.modemtestmode (versionCode=24, versionName=7.0) that contains an exported service app component named… | |
| Modificada | Alta (7.8) | 2.3% | — | Canvasgfx Canvas Draw | 1/10/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution. | |
| Modificada | Alta (7.8) | 1.5% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.… | |
| Modificada | Alta (7.8) | 1.5% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.… | |
| Modificada | Alta (7.8) | 1.5% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain the ability… | |
| Modificada | Alta (7.8) | 1.8% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code… | |
| Modificada | Alta (7.8) | 1.5% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain the ability to… | |
| Modificada | Alta (7.8) | 1.8% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution. A… | |
| Modificada | Media (5.4) | 0.77% | — | Cnvs Canvas | 9/2/2018 | 17/6/2026 | Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code. | |
| Modificada | Media (5.4) | 0.62% | — | Cnvs Canvas | 27/4/2017 | 17/6/2026 | cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users. | |
| Modificada | Media (6.8) | 31% | — | Skybluecanvas | 29/1/2014 | 17/6/2026 | The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php. | |
| Modificada | Media (4) | 2.4% | — | Skybluecanvas | 18/6/2009 | 16/6/2026 | Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Skybluecanvas | 18/6/2009 | 16/6/2026 | admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which reveals the installation path in an error message. | |
| Modificada | Media (4.3) | 1.5% | — | Skybluecanvas | 18/6/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) id, and (5) dir parameters. |