Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.2% | — | Ruckuswireless Zonedirector FirmwareRuckuswireless Unleashed Firmware | 13/10/2017 | 17/6/2026 | Ruckus Wireless Zone Director Controller firmware releases ZD9.x, ZD10.0.0.x, ZD10.0.1.x (less than 10.0.1.0.17 MR1 release) and Ruckus Wireless Unleashed AP Firmware releases 200.0.x, 200.1.x, 200.2.x, 200.3.x, 200.4.x. contain OS Command Injection vulnerabilities that could allow local authenticated users to execute… | |
| Modificada | Media (5) | 82% | 💥 Exploit | DrupalSecure Password Hashes Project Secure Passwords HashesDebian Linux | 24/11/2014 | 17/6/2026 | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request. | |
| Modificada | Media (5.4) | 0.27% | — | ABU ALI Anasheeds Project ABU ALI Anasheeds | 29/9/2014 | 17/6/2026 | The Abu Ali Anasheeds (aka com.faapps.abuali_anasheeds) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Quranedu Ahmed Bukhatir Nasheeds TV | 23/9/2014 | 17/6/2026 | The Ahmed Bukhatir Nasheeds TV (aka com.wAhmedBukhatirApp) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Playscape Bouncy Bill Monster Smasher ED | 9/9/2014 | 17/6/2026 | The Bouncy Bill Monster Smasher ed (aka mominis.Generic_Android.Bouncy_Bill_Monster_Smasher_Edition) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.2% | — | Slashes&dots Offria | 8/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to installer/index.php. | |
| Modificada | Media (5) | 1.3% | — | Unleashedmind IMG Assist | 4/1/2010 | 16/6/2026 | The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly enforce privilege requirements for unspecified pages, which allows remote attackers to read the (1) title or (2) body… | |
| Modificada | Baja (2.1) | 0.86% | — | Unleashedmind IMG Assist | 4/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, allows remote authenticated users, with image-node creation privileges, to inject arbitrary… | |
| Modificada | Alta (10) | 2.1% | — | Mark Reinsfelder Metashell | 10/9/2009 | 16/6/2026 | Unspecified vulnerability in metashell before 0.03 has unknown impact and attack vectors related to a "PATH execution security flaw," possibly an untrusted search path vulnerability. | |
| Modificada | Alta (9.3) | 1.9% | — | Secure Computing Secure WEB GatewaySecure Computing Webwasher | 12/12/2008 | 16/6/2026 | Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg… | |
| Modificada | Alta (7.1) | 1.4% | — | Secure Computing Webwasher | 15/4/2008 | 16/6/2026 | Unspecified vulnerability in Secure Computing Webwasher 5.30 before build 3159 and 6.3.0 before build 3150 allows remote attackers to cause a denial of service (freeze) via a crafted URL. | |
| Modificada | Media (4.3) | 2.0% | — | John Godley Search UnleashedWordpress Search Unleashed Plugin | 20/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the log feature in the John Godley Search Unleashed 0.2.10 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, which is not properly handled when the administrator views the log file. | |
| Modificada | Alta (7.1) | 1.5% | — | Mailwasher Server | 19/6/2007 | 16/6/2026 | MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | 20 20 Applications 20 20 Datashed | 22/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in 20/20 DataShed (aka Real Estate Listing System) allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) f-email.asp, or the (2) peopleID and (2) sort_order parameters to (b) listings.asp, different vectors than CVE-2006-5955. | |
| Modificada | Alta (7.5) | 1.4% | — | 20 20 Applications 20 20 Datashed | 17/11/2006 | 16/6/2026 | SQL injection vulnerability in listings.asp in 20/20 DataShed (aka Real Estate Listing System) allows remote attackers to execute arbitrary SQL commands via the itemID parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.6% | — | Webwasher CSM Appliance Suite | 23/12/2005 | 16/6/2026 | The encapsulation script mechanism in Webwasher CSM Appliance Suite 5.x uses case-sensitive detection of malicious tokens, which allows attackers to bypass script detection by using tokens that can be upper or lower case. NOTE: the vendor has stated that this problem could not be reproduced, and has asked the… | |
| Modificada | Alta (7.5) | 8.2% | 💥 Exploit | Webwasher Classic | 28/1/2005 | 16/6/2026 | WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions. | |
| Modificada | Alta (7.2) | 0.36% | — | Freebsd Slashem-tty | 31/12/2003 | 16/6/2026 | slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris. |