Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Instant-update Instant Update CMS26/6/201817/6/2026
Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application/controllers/administration/auth.php that can result in Account Tackover. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in v0.3.3.
ModificadaMedia (6.5)0.47%—Datenstrom Yellow5/5/201817/6/2026
The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.
ModificadaAlta (7.8)0.39%—Lenovo System Update4/5/201817/6/2026
MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as execution of arbitrary code. No additional…
ModificadaMedia (5.4)0.64%—Datenstrom Yellow4/5/201817/6/2026
A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have parserSafeMode=1 in system/config/config.ini to prevent XSS
ModificadaAlta (7.8)4.1%—Oisf Suricata-update18/4/201817/6/2026
OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. The "list-sources"-command is affected by this bug. that can result in Remote Code Execution(even as…
ModificadaMedia (4.7)0.36%—Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxRedhat Enterprise Linux+169/1/201817/6/2026
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption.…
ModificadaCrítica (9.8)2.9%💥 ExploitSoftdatepro Dating Software29/10/201717/6/2026
SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971.
ModificadaCrítica (9.8)2.0%💥 ExploitSoftdatepro Same Date PRO29/10/201717/6/2026
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.
ModificadaMedia (6.1)1.8%—DrupalJquery Update Project Jquery UpdateLabjs Project Labjs18/10/201717/6/2026
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this…
ModificadaAlta (7.8)0.47%—Lenovo System Update3/10/201717/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.
AnalizadaAlta (8.1)100%⚠ Explotación activa💥 ExploitApache TomcatNetapp 7-mode Transition ToolNetapp Oncommand BalanceNetapp Oncommand Shift+1819/9/20176/8/2026
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed…
ModificadaAlta (7)13%💥 ExploitLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux Server EUS+219/8/201717/6/2026
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
ModificadaCrítica (9.8)2.6%—Framasoft Framadate17/7/201717/6/2026
Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution
ModificadaAlta (7.5)0.73%—Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer20/6/201717/6/2026
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text…
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaAlta (7.8)0.50%—Lenovo System Update24/4/201717/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation…
ModificadaAlta (7)0.37%—Lenovo System Update24/4/201717/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability."
ModificadaAlta (8.1)3.3%—Lenovo Updates10/4/201717/6/2026
Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.
ModificadaAlta (8.1)1.5%—F-secure Software Updater11/3/201717/6/2026
F-Secure Software Updater 2.20, as distributed in several F-Secure products, downloads installation packages over plain http and does not perform file integrity validation after download. Man-in-the-middle attackers can replace the file with their own executable which will be executed under the SYSTEM account. Note…
ModificadaAlta (7.8)2.2%—Microsoft Auto Updater FOR MAC20/12/201617/6/2026
Untrusted search path vulnerability in Microsoft Auto Updater for Mac allows local users to gain privileges via a Trojan horse executable file, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability."
ModificadaMedia (4.8)1.00%—Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway25/10/201617/6/2026
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway.
ModificadaAlta (7.5)8.6%💥 ExploitCandidate-application-form Project Candidate-application-form6/10/201617/6/2026
Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin
ModificadaMedia (5.9)0.92%—Apple Software Update14/3/201617/6/2026
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.
ModificadaAlta (7.5)1.2%—Intel Driver Update Utility29/1/201617/6/2026
Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.
ModificadaMedia (6.5)83%—Sophos Unified Threat Management Up2dateISC DhcpDebian LinuxCanonical Ubuntu Linux14/1/201617/6/2026
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
Orbitaley — Vulnerabilidades