Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | 4homepages 4images | 5/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php. | |
| Modificada | Media (6) | 0.92% | — | HP System Management Homepage | 21/7/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Adobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+11 | 23/6/2015 | 17/6/2026 | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015. | |
| Modificada | Media (6.4) | 8.3% | — | Haxx CurlHaxx LibcurlHP System Management HomepageOracle Enterprise Manager OPS Center+1 | 22/6/2015 | 17/6/2026 | The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values. | |
| Modificada | Media (5) | 50% | — | Redhat Enterprise LinuxApple MAC OS XPHPHP System Management Homepage+8 | 9/6/2015 | 17/6/2026 | Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome. | |
| Modificada | Media (5) | 14% | — | Fedoraproject FedoraCanonical Ubuntu LinuxDebian LinuxApple MAC OS X+4 | 24/4/2015 | 17/6/2026 | cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request. | |
| Modificada | Alta (7.5) | 37% | — | Fedoraproject FedoraCanonical Ubuntu LinuxDebian LinuxHaxx Curl+5 | 24/4/2015 | 17/6/2026 | The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character. | |
| Modificada | Media (5) | 13% | — | Haxx CurlCanonical Ubuntu LinuxDebian LinuxHaxx Libcurl+2 | 24/4/2015 | 17/6/2026 | cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015. | |
| Modificada | Media (4) | 6.6% | 💥 Exploit | Etouch Samepage | 24/2/2015 | 17/6/2026 | Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filepath parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Etouch Samepage | 24/2/2015 | 17/6/2026 | SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed. | |
| Modificada | Media (4.3) | 0.94% | — | Homepage Decorator Perltreebbs | 13/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlTreeBBS 2.30 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.6% | — | HP System Management HomepageHp-ux | 19/10/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (4.3) | 2.4% | — | HP System Management Homepage | 2/10/2014 | 17/6/2026 | HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |
| Modificada | Media (6) | 0.86% | — | HP System Management Homepage | 2/10/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (4.3) | 3.9% | — | HP System Management Homepage | 2/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Homepage Decorator Perlmailer Project Homepage Decorator Perlmailer | 29/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlMailer 3.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.98% | — | HP System Management Homepage | 14/3/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (5) | 2.2% | — | HP System Management Homepage | 14/3/2014 | 16/6/2026 | Unspecified vulnerability in HP System Management Homepage (SMH) before 7.3 allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Media (4) | 1.9% | — | HP System Management Homepage | 23/9/2013 | 16/6/2026 | Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors. | |
| Modificada | Baja (3.5) | 1.3% | — | HP System Management Homepage | 22/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 3.3% | — | HP System Management Homepage | 22/7/2013 | 16/6/2026 | HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2356. | |
| Modificada | Baja (2.1) | 0.53% | — | HP System Management Homepage | 22/7/2013 | 16/6/2026 | Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows local users to cause a denial of service via unknown vectors, aka ZDI-CAN-1676. | |
| Modificada | Media (4.3) | 2.5% | — | HP System Management Homepage | 22/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.8% | — | HP System Management Homepage | 22/7/2013 | 16/6/2026 | Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2358, and CVE-2013-2359. | |
| Modificada | Media (4) | 1.8% | — | HP System Management Homepage | 22/7/2013 | 16/6/2026 | Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2358, and CVE-2013-2360. |