Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

59 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.67%—Apple Webobjects14/9/202217/6/2026
Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.
ModificadaAlta (7.8)0.63%💥 PoCLG Webos11/3/202217/6/2026
V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.
ModificadaCrítica (9.8)1.0%—LG Webos11/3/202217/6/2026
The public API error causes for the attacker to be able to bypass API access control.
ModificadaAlta (7.8)0.23%—LG Webos28/1/202217/6/2026
There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege
ModificadaAlta (8.8)2.4%—Vice Webopac15/11/202117/6/2026
Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services.
ModificadaMedia (6.1)0.63%—Vice Webopac15/11/202117/6/2026
Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax remotely, and further perform reflective XSS attacks.
ModificadaMedia (6.1)0.90%—Webodid Dropdown AND Scrollable Text10/9/202117/6/2026
The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.
ModificadaAlta (7.5)1.1%—Vertigis Weboffice17/2/202117/6/2026
VertiGIS WebOffice 10.7 SP1 before patch20210202 and 10.8 SP1 before patch20210207 allows attackers to achieve "Zugriff auf Inhalte der WebOffice Applikation."
ModificadaAlta (7.8)0.48%—LG Webos23/3/202017/6/2026
A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable files.
ModificadaAlta (7.5)1.3%—Weborf Project WeborfDebian Linux20/11/201916/6/2026
Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
ModificadaCrítica (9.8)4.0%—Themidnightcoders Weborb FOR Java11/6/201817/6/2026
The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive data on the server, denial of service, or…
ModificadaCrítica (9.8)8.2%—Themidnightcoders Weborb FOR Java11/6/201817/6/2026
The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection…
ModificadaAlta (7.8)0.45%—Advantech Webop25/10/201717/6/2026
A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer overflow, which may crash the process and allow an attacker to execute arbitrary code.
ModificadaMedia (4.3)2.2%—Debian LinuxKogmbh Webodf8/5/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebODF before 0.5.5, as used in ownCloud, allow remote attackers to inject arbitrary web script or HTML via a (1) style or (2) font name or (3) javascript or (4) data URI.
ModificadaMedia (4.3)2.2%—Kogmbh Webodf8/5/201517/6/2026
Cross-site scripting (XSS) vulnerability in WebODF before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via a file name.
ModificadaMedia (4.3)1.3%—Apple Webobjects9/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)3.9%💥 ExploitHP Palm PRE Webos13/9/201116/6/2026
The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating point exception.
ModificadaAlta (7.1)1.9%—HP Palm PRE Webos13/9/201116/6/2026
Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.
ModificadaMedia (4.3)1.5%—HP Palm Webos11/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in the Calendar application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.5%—HP Palm Webos11/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in the Contacts application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.2)0.49%—HP Palm Webos13/5/201116/6/2026
HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access.
ModificadaMedia (4.3)1.7%—HP Palm Webos13/5/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Email application in HP Palm webOS 1.4.5 and 1.4.5.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)2.4%—HP Palm PRE Webos19/4/201116/6/2026
Unspecified vulnerability in Palm Pre WebOS before 1.2.1 has unknown impact and attack vectors related to an "included contact template file."
ModificadaMedia (4.3)1.7%—HP Palm Webos8/12/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard file.
ModificadaMedia (5.6)1.2%—HP Palm Webos28/10/201016/6/2026
Unspecified vulnerability in the camera application in HP Palm webOS 1.4.1 allows local users to overwrite arbitrary files via unknown vectors.
Orbitaley — Vulnerabilidades