Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.9% | — | Codeasily Grand Flagallery | 18/10/2017 | 17/6/2026 | The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a request to (1) flagallery-skins/banner_widget_default/gallery.php or (2) flash-album-gallery/skins/banner_widget_default/gallery.php. | |
| Modificada | Media (4.3) | 7.1% | — | Codeasily Grand Flagallery | 1/10/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter. | |
| Modificada | Media (6.5) | 2.1% | — | Flag Module Project Flag | 17/5/2014 | 17/6/2026 | Eval injection vulnerability in the flag_import_form_validate function in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and earlier for Drupal allows remote authenticated administrators to execute arbitrary PHP code via the "Flag import code" text area to admin/structure/flags/import. NOTE: this issue… | |
| Modificada | Baja (2.1) | 0.94% | — | Joachim Noreiko Flag Module | 30/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "Administer flags" permission to inject arbitrary web script or HTML via the flag title. | |
| Modificada | Media (4.3) | 1.3% | — | Khalid Baheyeldin Flag Content | 13/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Flag Content module 5.x-2.x before 5.x-2.10 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Reason parameter. | |
| Modificada | Media (5) | 1.1% | — | Cisco Ironport Desktop Flag Plugin FOR Outlook | 14/5/2010 | 16/6/2026 | The Send Secure functionality in the Cisco IronPort Desktop Flag Plug-in for Outlook before 6.5.0-006 does not properly handle simultaneously composed messages, which might allow remote attackers to obtain cleartext contents of e-mail messages that were intended to be encrypted, aka bug 65623. | |
| Modificada | Alta (7.5) | 1.0% | — | Flagbit FB Filebase | 28/10/2009 | 16/6/2026 | SQL injection vulnerability in the Flagbit Filebase (fb_filebase) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 9.8% | — | Flagship Industries Ventrilo | 14/8/2008 | 16/6/2026 | The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784. | |
| Modificada | Alta (7.8) | 2.1% | — | Camouflage | 10/1/2007 | 16/6/2026 | Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information. | |
| Modificada | Media (5) | 4.5% | — | Bzflag Server | 29/12/2005 | 16/6/2026 | BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL (\0) character. | |
| Modificada | Media (5) | 7.8% | — | Flagship Industries Ventrilo | 30/8/2005 | 16/6/2026 | Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than specified in the packet header sent to UDP port 3784. | |
| Modificada | Media (6.2) | 0.75% | — | Multisoft Flagship | 20/10/2000 | 16/6/2026 | The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses. |