Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.55% | — | Northern.tech Cfengine | 26/4/2023 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials. | |
| Modificada | Media (5.5) | 0.36% | — | Northern.tech Cfengine | 10/3/2022 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files. | |
| Modificada | Media (5.5) | 0.35% | — | Northern.tech Cfengine | 10/3/2022 | 17/6/2026 | Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact. | |
| Modificada | Media (5.5) | 0.21% | — | Northern.tech Cfengine | 27/10/2021 | 17/6/2026 | The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. | |
| Modificada | Media (6.5) | 0.42% | — | Northern.tech Cfengine | 27/10/2021 | 17/6/2026 | CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation. | |
| Modificada | Media (6.1) | 0.64% | — | Northern.tech Cfengine | 16/4/2020 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0. | |
| Modificada | Alta (8.8) | 2.0% | — | Northern Cfengine | 6/6/2019 | 17/6/2026 | Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions. | |
| Modificada | Crítica (9.8) | 8.1% | 💥 Exploit | Fengoffice Feng Office | 7/3/2019 | 17/6/2026 | Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php. | |
| Modificada | Media (4.9) | 1.4% | — | Lfdycms LEI Feng TV CMS | 30/12/2018 | 17/6/2026 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows Directory Traversal via crafted use of ..* in Template/edit/path URIs, as demonstrated by the admin.php?s=/Template/edit/path/*web*..*..*..*..*1.txt.html URI to read the 1.txt file. | |
| Modificada | Alta (8.8) | 0.53% | — | Lfdycms LEI Feng TV CMS | 30/12/2018 | 17/6/2026 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF. | |
| Modificada | Alta (7.5) | 1.3% | — | Lfdycms LEI Feng TV CMS | 30/12/2018 | 17/6/2026 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI. | |
| Modificada | Alta (8) | 0.81% | — | Xunfeng Project Xunfeng | 12/9/2018 | 17/6/2026 | xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832. | |
| Modificada | Media (6.5) | 0.56% | — | Xunfeng Project Xunfeng | 11/9/2018 | 17/6/2026 | CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header. | |
| Modificada | Media (5.9) | 5.3% | — | Fiberhome Fengine S5800 Firmware | 23/1/2017 | 17/6/2026 | An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger an increase in the SSH login timeout (each of the login attempts will occupy a connection slot for a… | |
| Modificada | Media (4.3) | 1.9% | — | Fengoffice Feng Office | 19/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field. | |
| Modificada | Media (4.3) | 0.96% | — | Fengoffice Feng Office | 28/10/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Feng Office 2.3.2-rc and earlier allows remote attackers to inject arbitrary web script or HTML via an arbitrary ref_XXX parameter. | |
| Modificada | Media (5) | 1.3% | — | Fengoffice Feng Office | 23/9/2011 | 16/6/2026 | Feng Office 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files. | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Baofeng Storm | 27/7/2009 | 16/6/2026 | Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist file. | |
| Modificada | Alta (9.3) | 7.5% | 💥 Exploit | Baofeng Storm | 28/5/2009 | 16/6/2026 | Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009. | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Baofeng Storm | 11/5/2009 | 16/6/2026 | Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (5) | 1.8% | — | Feng | 4/1/2008 | 16/6/2026 | Interpretation conflict in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a User-Agent header line that contains a carriage-return character, which is considered a line delimiter when the header is split into individual lines, but not when… | |
| Modificada | Alta (7.5) | 4.1% | — | Feng | 4/1/2008 | 16/6/2026 | Multiple buffer overflows in the RTSP_valid_response_msg function in RTSP_state_machine.c in LScube Feng 0.1.15 and earlier allow remote attackers to execute arbitrary code via (1) a long first line of a response, as demonstrated by a long VER line; or (2) a long second line of a response, as demonstrated by a message… | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Feng | 4/1/2008 | 16/6/2026 | The Url_init function in utils/url.c in Netembryo 0.0.4, when used by LScube Feng, allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a malformed URI containing a "/:" sequence, as demonstrated by a "DESCRIBE /: RTSP/1.0" request. | |
| Modificada | Alta (7.5) | 3.8% | — | Feng | 4/1/2008 | 16/6/2026 | Integer overflow in the RTSP_remove_msg function in RTSP_lowlevel.c in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an RTP packet with a size value of 0xffff. | |
| Modificada | Media (5) | 2.1% | — | Feng | 4/1/2008 | 16/6/2026 | LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port"… |