Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.22%—Netop Vision PRO25/3/202117/6/2026
Local privilege escalation vulnerability in Windows clients of Netop Vision Pro up to and including 9.7.1 allows a local user to gain administrator privileges whilst using the clients.
ModificadaMedia (6.1)1.2%💥 ExploitMageewp Onetone3/4/202017/6/2026
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
ModificadaMedia (5.3)2.4%💥 ExploitMageewp Onetone3/4/202017/6/2026
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
ModificadaAlta (7.5)1.1%—Gemstonetoken Project Gemstonetoken9/7/201817/6/2026
The mintToken function of a smart contract implementation for GemstoneToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaMedia (5.5)0.84%—Netop Remote Control9/1/201717/6/2026
Stack-based buffer overflow vulnerability in Netop Remote Control versions 11.53, 12.21 and prior. The affected module in the Guest client is the "Import to Phonebook" option. When a specially designed malicious file containing special characters is loaded, the overflow occurs. 12.51 is the fixed version. The Support…
ModificadaCrítica (9.8)4.5%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.
ModificadaCrítica (9.8)4.5%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
ModificadaAlta (7.5)3.9%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.
ModificadaAlta (7.5)2.2%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.
ModificadaMedia (5.4)0.27%—Planetofthevapes Planet OF THE Vapes Forum23/9/201417/6/2026
The Planet of the Vapes Forum (aka com.tapatalk.planetofthevapescoukforums) application 3.7.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.5%💥 ExploitOnlinetools Easyimagecatalogue1/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in onlinetools.org EasyImageCatalogue 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search and (2) d index.php parameters to index.php, (3) dir parameter to thumber.php, and the d parameter to (4) describe.php and (5) addcomment.php.…
ModificadaAlta (7.5)11%💥 ExploitNetoffice Dwins1/5/200816/6/2026
includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, which allows remote attackers to bypass authentication and execute arbitrary code by setting this variable to 1, as demonstrated by uploading a PHP script via an add action…
ModificadaAlta (10)69%💥 ExploitNetopia Timbuktu PRO14/3/200816/6/2026
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \ (backslash) character followed by ../ (dot dot…
ModificadaAlta (7.5)2.9%💥 ExploitNetopia Timbuktu PRO14/3/200816/6/2026
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user…
ModificadaMedia (5)1.7%—Netopia Timbuktu PRO14/3/200816/6/2026
The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version field or (2) a denial of service (CPU consumption and daemon termination) via an invalid or partial message.
ModificadaAlta (7.2)0.35%—Motorola Netoctopus9/1/200816/6/2026
The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR)…
ModificadaAlta (7.5)6.3%💥 ExploitNetofficePhpcollab30/3/200616/6/2026
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.
ModificadaMedia (5)1.4%—Netobjects Fusion30/11/200516/6/2026
NetObjects Fusion 9 (NOF9) allows remote attackers to obtain sensitive information, including passwords, by downloading the _versioning_repository_/rollbacklog.xml file, then using it to download and modify the associated ZIP file to edit and republish the site.
ModificadaMedia (5)2.2%—Danware Data Netop9/2/200516/6/2026
NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when responses are disabled, a "custom" HELO request.
ModificadaAlta (10)16%💥 ExploitMichael Kohn Ringtonetools10/1/200516/6/2026
Buffer overflow in the parse_emelody function in parse_emelody.c for ringtonetools 2.22 allows remote attackers to execute arbitrary code via a crafted eMelody file.
ModificadaMedia (5)2.0%—Netopia Timbuktu PRO MAC23/12/200416/6/2026
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.
ModificadaMedia (5)1.4%—Onlinetools.org Phpimageview31/12/200216/6/2026
phpimageview.php in PHPImageView 1.0 allows remote attackers to obtain sensitive information via the pw=show option, which invokes the phpinfo function.
ModificadaMedia (6.8)1.3%—Onlinetools.org Phpimageview31/12/200216/6/2026
Cross-site scripting vulnerability (XSS) in phpimageview.php for PHPImageView 1.0 allows remote attackers to execute arbitrary script as other users via the pic parameter.
ModificadaMedia (5)3.2%💥 ExploitNetopia Timbuktu PRO25/3/200216/6/2026
Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420).
ModificadaMedia (4.6)0.33%—Crosstec Corporation Netop School11/9/200116/6/2026
NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the student version, closing the student version, then starting the administration version.
Orbitaley — Vulnerabilidades