Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.6% | — | Instant-update Instant Update CMS | 26/6/2018 | 17/6/2026 | Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application/controllers/administration/auth.php that can result in Account Tackover. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in v0.3.3. | |
| Modificada | Media (6.5) | 0.47% | — | Datenstrom Yellow | 5/5/2018 | 17/6/2026 | The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles. | |
| Modificada | Alta (7.8) | 0.39% | — | Lenovo System Update | 4/5/2018 | 17/6/2026 | MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as execution of arbitrary code. No additional… | |
| Modificada | Media (5.4) | 0.64% | — | Datenstrom Yellow | 4/5/2018 | 17/6/2026 | A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have parserSafeMode=1 in system/config/config.ini to prevent XSS | |
| Modificada | Alta (7.8) | 4.1% | — | Oisf Suricata-update | 18/4/2018 | 17/6/2026 | OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. The "list-sources"-command is affected by this bug. that can result in Remote Code Execution(even as… | |
| Modificada | Media (4.7) | 0.36% | — | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxRedhat Enterprise Linux+16 | 9/1/2018 | 17/6/2026 | A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption.… | |
| Modificada | Crítica (9.8) | 2.9% | 💥 Exploit | Softdatepro Dating Software | 29/10/2017 | 17/6/2026 | SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 Exploit | Softdatepro Same Date PRO | 29/10/2017 | 17/6/2026 | Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972. | |
| Modificada | Media (6.1) | 1.8% | — | DrupalJquery Update Project Jquery UpdateLabjs Project Labjs | 18/10/2017 | 17/6/2026 | Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this… | |
| Modificada | Alta (7.8) | 0.47% | — | Lenovo System Update | 3/10/2017 | 17/6/2026 | Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables. | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatNetapp 7-mode Transition ToolNetapp Oncommand BalanceNetapp Oncommand Shift+18 | 19/9/2017 | 6/8/2026 | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed… | |
| Modificada | Alta (7) | 13% | 💥 Exploit | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux Server EUS+2 | 19/8/2017 | 17/6/2026 | Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing. | |
| Modificada | Crítica (9.8) | 2.6% | — | Framasoft Framadate | 17/7/2017 | 17/6/2026 | Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution | |
| Modificada | Alta (7.5) | 0.73% | — | Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer | 20/6/2017 | 17/6/2026 | If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text… | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Alta (7.8) | 0.50% | — | Lenovo System Update | 24/4/2017 | 17/6/2026 | Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation… | |
| Modificada | Alta (7) | 0.37% | — | Lenovo System Update | 24/4/2017 | 17/6/2026 | Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability." | |
| Modificada | Alta (8.1) | 3.3% | — | Lenovo Updates | 10/4/2017 | 17/6/2026 | Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code. | |
| Modificada | Alta (8.1) | 1.5% | — | F-secure Software Updater | 11/3/2017 | 17/6/2026 | F-Secure Software Updater 2.20, as distributed in several F-Secure products, downloads installation packages over plain http and does not perform file integrity validation after download. Man-in-the-middle attackers can replace the file with their own executable which will be executed under the SYSTEM account. Note… | |
| Modificada | Alta (7.8) | 2.2% | — | Microsoft Auto Updater FOR MAC | 20/12/2016 | 17/6/2026 | Untrusted search path vulnerability in Microsoft Auto Updater for Mac allows local users to gain privileges via a Trojan horse executable file, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." | |
| Modificada | Media (4.8) | 1.00% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway. | |
| Modificada | Alta (7.5) | 8.6% | 💥 Exploit | Candidate-application-form Project Candidate-application-form | 6/10/2016 | 17/6/2026 | Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin | |
| Modificada | Media (5.9) | 0.92% | — | Apple Software Update | 14/3/2016 | 17/6/2026 | Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream. | |
| Modificada | Alta (7.5) | 1.2% | — | Intel Driver Update Utility | 29/1/2016 | 17/6/2026 | Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (6.5) | 83% | — | Sophos Unified Threat Management Up2dateISC DhcpDebian LinuxCanonical Ubuntu Linux | 14/1/2016 | 17/6/2026 | ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet. |