Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.8% | — | Apple IworkApple Pages | 18/10/2015 | 17/6/2026 | The Apple iWork application before 2.6 for iOS and Apple Pages before 5.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Pages document. | |
| Modificada | Media (6.8) | 2.9% | — | Apple NumbersApple PagesApple KeynoteApple Iwork | 18/10/2015 | 17/6/2026 | The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document. | |
| Modificada | Media (4.3) | 2.0% | — | Apple NumbersApple IworkApple PagesApple Keynote | 18/10/2015 | 17/6/2026 | The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document. | |
| Modificada | Media (5) | 2.5% | — | Apple MAC OS XApple Iphone OSApple NumbersApple Keynote+2 | 16/8/2015 | 17/6/2026 | Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (5) | 13% | — | Iwork Webglimpse | 19/3/2012 | 16/6/2026 | Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter. | |
| Modificada | Media (4.3) | 0.95% | — | Iwork Webglimpse | 19/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the DOC parameter. | |
| Modificada | Media (5) | 5.3% | — | Iwork Webglimpse | 19/3/2012 | 16/6/2026 | wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request. | |
| Modificada | Alta (7.5) | 15% | — | Miniwork COM Canteen | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php. |