Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.92% | — | Lenovo Bootable USB | 10/4/2019 | 17/6/2026 | A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local access to execute code on the system. | |
| Modificada | Crítica (9.8) | 4.9% | — | Getbootstrap Bootstrap-sass | 4/4/2019 | 17/6/2026 | Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note… | |
| Modificada | Alta (7) | 0.28% | — | Denx U-boot | 21/3/2019 | 17/6/2026 | An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To… | |
| Modificada | Media (6.1) | 16% | 💥 PoC | Getbootstrap BootstrapF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+12 | 20/2/2019 | 17/6/2026 | In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. | |
| Modificada | Alta (7.2) | 1.3% | — | Pbootcms | 17/2/2019 | 17/6/2026 | A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php. | |
| Modificada | Media (6.5) | 0.54% | — | Pbootcms | 7/2/2019 | 17/6/2026 | A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI. | |
| Modificada | Media (6.1) | 4.0% | — | Getbootstrap Bootstrap | 9/1/2019 | 17/6/2026 | In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. | |
| Modificada | Media (6.1) | 3.8% | — | Getbootstrap Bootstrap | 9/1/2019 | 17/6/2026 | In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. | |
| Modificada | Media (6.1) | 4.0% | 💥 PoC | Getbootstrap Bootstrap | 9/1/2019 | 17/6/2026 | In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pbootcms | 6/12/2018 | 17/6/2026 | SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string. | |
| Modificada | Crítica (9.8) | 3.9% | — | Pbootcms | 27/11/2018 | 17/6/2026 | PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect apps\home\controller\ParserController.php parserIfLabel protection… | |
| Modificada | Alta (7.8) | 0.57% | — | Denx U-boot | 20/11/2018 | 17/6/2026 | DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled. | |
| Modificada | Crítica (9.8) | 2.0% | — | Denx U-boot | 20/11/2018 | 17/6/2026 | DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a crafted kernel image. | |
| Modificada | Alta (7.2) | 1.4% | — | Pbootcms | 7/11/2018 | 17/6/2026 | PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pbootcms | 17/10/2018 | 17/6/2026 | apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI. | |
| Modificada | Alta (8.1) | 0.88% | — | Pbootcms | 10/10/2018 | 17/6/2026 | PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI. | |
| Modificada | Media (4.8) | 0.53% | — | Springboot Authority Project Springboot Authority | 23/9/2018 | 17/6/2026 | An issue was discovered in springboot_authority through 2017-03-06. There is stored XSS via the admin/role/edit roleKey, name, or description parameter. | |
| Modificada | Media (5.3) | 0.95% | — | Ajax Bootmodal Login Project Ajax Bootmodal Login | 26/8/2018 | 17/6/2026 | An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and password-recovery form require solving a CAPTCHA to perform actions. However, this is required only once per user session, and therefore one could send as many requests as one wished by automation. | |
| Modificada | Media (6.4) | 0.27% | — | Denx U-boot | 24/7/2018 | 17/6/2026 | Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryption feature using environment encryption (i.e., setting the configuration parameter CONFIG_ENV_AES=y) read environment variables from disk as the encrypted disk image is… | |
| Modificada | Media (4.6) | 0.31% | — | Denx U-boot | 24/7/2018 | 17/6/2026 | Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. For devices utilizing this environment encryption mode, U-Boot's use of a zero initialization vector may allow attacks against the underlying cryptographic implementation and allow an attacker to decrypt the data. Das… | |
| Modificada | Media (6.1) | 4.0% | 💥 PoC | Getbootstrap Bootstrap | 13/7/2018 | 17/6/2026 | In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. | |
| Modificada | Media (6.1) | 4.3% | 💥 PoC | Getbootstrap Bootstrap | 13/7/2018 | 17/6/2026 | In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. | |
| Modificada | Media (6.1) | 4.1% | 💥 PoC | Debian LinuxGetbootstrap Bootstrap | 13/7/2018 | 17/6/2026 | In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. | |
| Modificada | Media (5.5) | 0.71% | — | Denx U-boot | 26/6/2018 | 17/6/2026 | U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special device memory functionality. | |
| Modificada | Media (4.6) | 0.34% | — | Ecos Secure Boot Stick Firmware | 17/6/2018 | 17/6/2026 | Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to partially extract confidential configurations via user-space emulation. |