Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.67% | — | Apple Webobjects | 14/9/2022 | 17/6/2026 | Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces. | |
| Modificada | Alta (7.8) | 0.63% | 💥 PoC | LG Webos | 11/3/2022 | 17/6/2026 | V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models. | |
| Modificada | Crítica (9.8) | 1.0% | — | LG Webos | 11/3/2022 | 17/6/2026 | The public API error causes for the attacker to be able to bypass API access control. | |
| Modificada | Alta (7.8) | 0.23% | — | LG Webos | 28/1/2022 | 17/6/2026 | There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege | |
| Modificada | Alta (8.8) | 2.4% | — | Vice Webopac | 15/11/2021 | 17/6/2026 | Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services. | |
| Modificada | Media (6.1) | 0.63% | — | Vice Webopac | 15/11/2021 | 17/6/2026 | Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax remotely, and further perform reflective XSS attacks. | |
| Modificada | Media (6.1) | 0.90% | — | Webodid Dropdown AND Scrollable Text | 10/9/2021 | 17/6/2026 | The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0. | |
| Modificada | Alta (7.5) | 1.1% | — | Vertigis Weboffice | 17/2/2021 | 17/6/2026 | VertiGIS WebOffice 10.7 SP1 before patch20210202 and 10.8 SP1 before patch20210207 allows attackers to achieve "Zugriff auf Inhalte der WebOffice Applikation." | |
| Modificada | Alta (7.8) | 0.48% | — | LG Webos | 23/3/2020 | 17/6/2026 | A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable files. | |
| Modificada | Alta (7.5) | 1.3% | — | Weborf Project WeborfDebian Linux | 20/11/2019 | 16/6/2026 | Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP. | |
| Modificada | Crítica (9.8) | 4.0% | — | Themidnightcoders Weborb FOR Java | 11/6/2018 | 17/6/2026 | The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive data on the server, denial of service, or… | |
| Modificada | Crítica (9.8) | 8.2% | — | Themidnightcoders Weborb FOR Java | 11/6/2018 | 17/6/2026 | The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection… | |
| Modificada | Alta (7.8) | 0.45% | — | Advantech Webop | 25/10/2017 | 17/6/2026 | A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer overflow, which may crash the process and allow an attacker to execute arbitrary code. | |
| Modificada | Media (4.3) | 2.2% | — | Debian LinuxKogmbh Webodf | 8/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebODF before 0.5.5, as used in ownCloud, allow remote attackers to inject arbitrary web script or HTML via a (1) style or (2) font name or (3) javascript or (4) data URI. | |
| Modificada | Media (4.3) | 2.2% | — | Kogmbh Webodf | 8/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in WebODF before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via a file name. | |
| Modificada | Media (4.3) | 1.3% | — | Apple Webobjects | 9/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 3.9% | 💥 Exploit | HP Palm PRE Webos | 13/9/2011 | 16/6/2026 | The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating point exception. | |
| Modificada | Alta (7.1) | 1.9% | — | HP Palm PRE Webos | 13/9/2011 | 16/6/2026 | Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3. | |
| Modificada | Media (4.3) | 1.5% | — | HP Palm Webos | 11/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Calendar application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | HP Palm Webos | 11/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Contacts application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.49% | — | HP Palm Webos | 13/5/2011 | 16/6/2026 | HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access. | |
| Modificada | Media (4.3) | 1.7% | — | HP Palm Webos | 13/5/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Email application in HP Palm webOS 1.4.5 and 1.4.5.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 2.4% | — | HP Palm PRE Webos | 19/4/2011 | 16/6/2026 | Unspecified vulnerability in Palm Pre WebOS before 1.2.1 has unknown impact and attack vectors related to an "included contact template file." | |
| Modificada | Media (4.3) | 1.7% | — | HP Palm Webos | 8/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard file. | |
| Modificada | Media (5.6) | 1.2% | — | HP Palm Webos | 28/10/2010 | 16/6/2026 | Unspecified vulnerability in the camera application in HP Palm webOS 1.4.1 allows local users to overwrite arbitrary files via unknown vectors. |