Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.4%—4homepages 4images5/10/201517/6/2026
Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php.
ModificadaMedia (6)0.92%—HP System Management Homepage21/7/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitAdobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+1123/6/201517/6/2026
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
ModificadaMedia (6.4)8.3%—Haxx CurlHaxx LibcurlHP System Management HomepageOracle Enterprise Manager OPS Center+122/6/201517/6/2026
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
ModificadaMedia (5)50%—Redhat Enterprise LinuxApple MAC OS XPHPHP System Management Homepage+89/6/201517/6/2026
Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.
ModificadaMedia (5)14%—Fedoraproject FedoraCanonical Ubuntu LinuxDebian LinuxApple MAC OS X+424/4/201517/6/2026
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
ModificadaAlta (7.5)37%—Fedoraproject FedoraCanonical Ubuntu LinuxDebian LinuxHaxx Curl+524/4/201517/6/2026
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.
ModificadaMedia (5)13%—Haxx CurlCanonical Ubuntu LinuxDebian LinuxHaxx Libcurl+224/4/201517/6/2026
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
ModificadaMedia (4)6.6%💥 ExploitEtouch Samepage24/2/201517/6/2026
Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filepath parameter.
ModificadaAlta (7.5)2.4%💥 ExploitEtouch Samepage24/2/201517/6/2026
SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed.
ModificadaMedia (4.3)0.94%—Homepage Decorator Perltreebbs13/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlTreeBBS 2.30 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)1.6%—HP System Management HomepageHp-ux19/10/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (4.3)2.4%—HP System Management Homepage2/10/201417/6/2026
HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
ModificadaMedia (6)0.86%—HP System Management Homepage2/10/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (4.3)3.9%—HP System Management Homepage2/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.1%—Homepage Decorator Perlmailer Project Homepage Decorator Perlmailer29/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlMailer 3.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.98%—HP System Management Homepage14/3/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (5)2.2%—HP System Management Homepage14/3/201416/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.3 allows remote attackers to obtain sensitive information via unknown vectors.
ModificadaMedia (4)1.9%—HP System Management Homepage23/9/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors.
ModificadaBaja (3.5)1.3%—HP System Management Homepage22/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)3.3%—HP System Management Homepage22/7/201316/6/2026
HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2356.
ModificadaBaja (2.1)0.53%—HP System Management Homepage22/7/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows local users to cause a denial of service via unknown vectors, aka ZDI-CAN-1676.
ModificadaMedia (4.3)2.5%—HP System Management Homepage22/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4)1.8%—HP System Management Homepage22/7/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2358, and CVE-2013-2359.
ModificadaMedia (4)1.8%—HP System Management Homepage22/7/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2358, and CVE-2013-2360.
Orbitaley — Vulnerabilidades