Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.9% | 💥 Exploit | Apachefriends Xampp | 14/5/2019 | 17/6/2026 | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued. | |
| Modificada | Media (5.4) | 0.27% | — | Tequilagames Battlefriends AT SEA Gold | 21/10/2014 | 17/6/2026 | The BattleFriends at Sea GOLD (aka com.tequilamobile.warshipslivegold) application 1.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Xlabz Sketch W Friends Free -tablets | 11/10/2014 | 17/6/2026 | The Sketch W Friends FREE -Tablets (aka air.com.xlabz.SketchWFriendsFree) application 5.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 5.2% | 💥 Exploit | Apachefriends Xampp | 29/9/2014 | 16/6/2026 | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method. | |
| Modificada | Media (5.4) | 0.27% | — | Lotum Paint-for-friends | 9/9/2014 | 17/6/2026 | The Paint for Friends (aka de.lotumlabs.buddypainting) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.2% | — | Friends OF Symfony Project Fosuserbundle | 25/9/2013 | 16/6/2026 | The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation. | |
| Modificada | Media (4.3) | 0.85% | — | Typo3 Mimi Tipfriends | 15/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Tip many friends (mimi_tipfriends) extension 0.0.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.5) | 1.6% | 💥 Exploit | Apachefriends Xampp | 20/3/2009 | 16/6/2026 | security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1. | |
| Modificada | Media (6.8) | 1.0% | 💥 Exploit | Apachefriends Xampp | 20/3/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter. | |
| Modificada | Alta (7.5) | 9.0% | — | Apachefriends Xampp | 16/3/2009 | 16/6/2026 | XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL… | |
| Modificada | Media (4.3) | 1.0% | — | Apache Friends Xampp | 6/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in adodb.php in XAMPP for Windows 1.6.8 allows remote attackers to inject arbitrary web script or HTML via the (1) dbserver, (2) host, (3) user, (4) password, (5) database, and (6) table parameters. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | Apache Friends Xampp | 10/8/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the text parameter to (1) iart.php and (2) ming.php. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Alstrasoft E-friends | 23/11/2007 | 16/6/2026 | SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewevent action. | |
| Modificada | Media (6.4) | 1.3% | — | Alstrasoft E-friends | 30/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php AlstraSoft E-Friends allows remote attackers to inject arbitrary web script or HTML via the p_id parameter in a people_card action. NOTE: this might overlap CVE-2006-2564. | |
| Modificada | Alta (10) | 1.8% | 💥 Exploit | Alstrasoft E-friends | 22/5/2007 | 16/6/2026 | SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal action for index.php. | |
| Modificada | Media (4.6) | 0.38% | — | Apachefriends Xampp | 26/9/2006 | 16/6/2026 | Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted… | |
| Modificada | Alta (7.5) | 9.7% | 💥 Exploit | Alstrasoft E-friends | 21/9/2006 | 16/6/2026 | Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary code via a .. (dot dot) sequence and trailing null (%00) byte in the lang parameter, as demonstrated by injecting PHP code into a log file. | |
| Modificada | Media (4.3) | 1.3% | — | Alstrasoft E-friends | 24/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlstraSoft E-Friends allow remote attackers to inject arbitrary web script or HTML by (1) posting a blog, (2) posting a listing, (3) posting an event, (4) adding comments, or (5) sending a message. | |
| Modificada | Alta (7.5) | 1.7% | — | Alstrasoft E-friends | 27/9/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via the mode parameter. |