Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.8% | — | Linagora Hublin | 23/7/2019 | 17/6/2026 | LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact is: The vulnerability allows an attacker to access any file (with a fixed extension) on the server. The component is: A web-view renderer; details here:… | |
| Modificada | Alta (7.5) | 6.0% | — | Shellinabox Project Shellinabox | 21/3/2019 | 17/6/2026 | libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down. | |
| Modificada | Media (5.5) | 0.66% | — | Huawei Agassi-l09 FirmwareHuawei Agassi-w09 FirmwareHuawei Baggio2-u01a FirmwareHuawei Bond-al00c Firmware+15 | 26/9/2018 | 17/6/2026 | Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, AGS-L09C229B003CUSTC229D001, Agassi-W09 AGS-W09C100B257CUSTC100D001, AGS-W09C128B252CUSTC128D001, AGS-W09C170B252CUSTC170D001, AGS-W09C229B251CUSTC229D001, AGS-W09C331B003CUSTC331D001,… | |
| Modificada | Alta (8.8) | 2.5% | — | Linaro LavaDebian Linux | 19/6/2018 | 17/6/2026 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur. | |
| Modificada | Media (6.5) | 1.5% | — | Linaro LavaDebian Linux | 19/6/2018 | 17/6/2026 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml. | |
| Modificada | Media (6.5) | 0.89% | — | Linaro Lava | 19/6/2018 | 17/6/2026 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml. | |
| Modificada | Media (5.9) | 1.6% | — | Linaro Op-tee | 2/1/2018 | 17/6/2026 | Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key. | |
| Modificada | Alta (7.5) | 1.9% | — | Linaro Op-tee | 2/1/2018 | 17/6/2026 | Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key. | |
| Modificada | Media (5.9) | 0.49% | — | Meafinancial Oculina Mobile Banking | 16/6/2017 | 17/6/2026 | The "Oculina Mobile Banking" by Oculina Bank app 3.0.0 -- aka oculina-mobile-banking/id867025690 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.4) | 2.0% | — | Fedoraproject FedoraShellinabox Project Shellinabox | 12/1/2016 | 17/6/2026 | The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL. | |
| Modificada | Alta (7.5) | 1.2% | — | Lina Wolf SEO Pack FOR TT News | 27/6/2013 | 16/6/2026 | SQL injection vulnerability in the SEO Pack for tt_news extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Celina Jorge Facil CMS | 8/9/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) change_lang parameter to index.php or (2) modload parameter to modules.php. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Smolinari Mini WEB Calendar | 13/11/2008 | 16/6/2026 | Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory traversal sequences in the thefile parameter. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Smolinari Mini WEB Calendar | 13/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Alta (7.2) | 1.6% | 💥 Exploit | Jacques Gelinas Linuxconf | 2/4/2003 | 16/6/2026 | Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated. | |
| Modificada | Alta (7.5) | 2.5% | — | Jacques Gelinas Linuxconf | 12/11/2002 | 16/6/2026 | The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail relay, which allows remote attackers to send Spam email. |