Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

41 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.32%💥 PoCFulldive Full Dialer13/9/202317/6/2026
The com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.full.dialer.top.secure.encrypted.activities.DialerActivity component.
ModificadaMedia (5.3)1.4%—Divebook Project Divebook8/12/202017/6/2026
The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filter_diver parameter.
ModificadaMedia (6.1)0.96%—Divebook Project Divebook8/12/202017/6/2026
The DiveBook plugin 1.1.4 for WordPress is prone to unauthenticated XSS within the filter function (via an arbitrary parameter).
ModificadaMedia (5.3)1.2%—Divebook Project Divebook8/12/202017/6/2026
The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
ModificadaAlta (8.8)3.1%💥 ExploitAdive Framework26/1/202017/6/2026
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
ModificadaMedia (6.1)0.87%—Adive Framework26/1/202017/6/2026
Adive Framework 2.0.8 has admin/user/add userName XSS.
ModificadaMedia (6.1)0.87%—Adive Framework26/1/202017/6/2026
Adive Framework 2.0.8 has admin/user/add userUsername XSS.
ModificadaAlta (8.8)9.3%💥 ExploitSchben Adive6/8/201917/6/2026
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.
ModificadaAlta (8.8)2.7%💥 ExploitSchben Adive6/8/201917/6/2026
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
ModificadaMedia (5.5)2.2%💥 ExploitBlackwave Dive Assistant12/9/201717/6/2026
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.
ModificadaMedia (5.4)0.27%—Paperton Dive THE World4/10/201417/6/2026
The Dive The World (aka com.paperton.wl.divetheworld) application 1.53 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.6%—Diversesolutions Dsidxpress IDX Plugin1/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in client-assist.php in the dsIDXpress IDX plugin before 2.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaBaja (3.3)1.6%—Samsungdive31/12/201216/6/2026
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of remote tracking, which might allow physically proximate attackers to defeat a product-recovery effort by tampering with this feature or its location data.
ModificadaBaja (2.9)1.3%—Samsungdive31/12/201216/6/2026
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly implement Location APIs, which allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."
ModificadaMedia (4.3)1.3%—Scriptsolutions Perldiver27/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in perldiver.cgi in PerlDiver 2.x allows remote attackers to inject arbitrary web script or HTML via the module parameter.
ModificadaMedia (4.3)1.4%—Scriptsolutions Perldiver27/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver 1.x allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.
Orbitaley — Vulnerabilidades