Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.74% | — | Forget Heart Message BOX Project Forget Heart Message BOX | 1/2/2023 | 17/6/2026 | Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php. | |
| Modificada | Media (5.4) | 0.53% | — | Techearty Easy Accordion | 16/1/2023 | 17/6/2026 | The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.47% | — | Techearty Carousel, Slider, Gallery BY WP Carousel | 16/1/2023 | 17/6/2026 | The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high… | |
| Modificada | Media (6.5) | 6.7% | — | Heartex Label Studio | 3/10/2022 | 9/7/2026 | A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker… | |
| Modificada | Media (5.4) | 0.62% | — | Techearty Easy Accordion | 11/10/2021 | 17/6/2026 | The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion. | |
| Modificada | Media (6.1) | 0.69% | — | Heartland Payment Systems Heartland-php | 21/4/2017 | 17/6/2026 | Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples/consumer-authentication/cruise.php via the URI, as demonstrated by the cavv parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Runtastic Heart Rate | 9/9/2014 | 17/6/2026 | The Runtastic Heart Rate (aka com.runtastic.android.heartrate.lite) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.29% | — | Chat Flirt & Dating Heart Jaumo | 9/9/2014 | 17/6/2026 | The Chat, Flirt & Dating Heart JAUMO (aka com.jaumo) application 2.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Choiceoflove Free Dating Heart COL | 9/9/2014 | 17/6/2026 | The Free Dating Heart COL (aka com.choiceoflove.dating) application 2.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.8% | — | Heart5 Statpresscn | 25/1/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/admin.php in the StatPressCN plugin 1.9.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) what1, (2) what2, (3) what3, (4) what4, and (5) what5 parameters. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Baja (3.5) | 0.87% | — | Menhir Heartbeat | 25/5/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat module 6.x before 6.x-4.9 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Heartlogic Hl-sitemanager | 9/4/2010 | 16/6/2026 | SQL injection vulnerability in Heartlogic HL-SiteManager allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Alta (7.1) | 2.5% | — | Linux-ha Heartbeat | 8/8/2007 | 16/6/2026 | XHA (Linux-HA) on the BlueCat Networks Adonis DNS/DHCP Appliance 5.0.2.8 allows remote attackers to cause a denial of service (heartbeat control process crash) via a UDP packet to port 694. NOTE: this may be the same as CVE-2006-3121. | |
| Modificada | Media (5) | 14% | — | High Availability Linux Project Heartbeat | 17/8/2006 | 16/6/2026 | The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial of service (crash) via the length parameter in a heartbeat message. | |
| Modificada | Baja (2.1) | 0.78% | — | Linux-ha Heartbeat | 25/7/2006 | 16/6/2026 | heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup. | |
| Modificada | Alta (7.5) | 1.4% | — | Enterprise Heart Enterprise Connector | 29/12/2005 | 16/6/2026 | SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875. | |
| Modificada | Alta (7.5) | 1.2% | — | Enterprise Heart Enterprise Connector | 29/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php. | |
| Modificada | Baja (2.1) | 0.36% | — | High Availability Linux Project Heartbeat | 12/7/2005 | 16/6/2026 | High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (10) | 6.3% | — | Linux-ha Heartbeat | 28/10/2002 | 16/6/2026 | Multiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers to execute arbitrary code via certain packets to UDP port 694 (incorrectly claimed as TCP in some sources). |