Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.76% | — | Firefly-iii Firefly III | 5/8/2019 | 17/6/2026 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page. | |
| Modificada | Media (5.4) | 0.76% | — | Firefly-iii Firefly III | 5/8/2019 | 17/6/2026 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transaction link. | |
| Modificada | Media (6.1) | 1.3% | — | Firefly-iii Firefly III | 5/8/2019 | 17/6/2026 | Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during a convert transaction action. | |
| Modificada | Media (5.4) | 0.76% | — | Firefly-iii Firefly III | 18/7/2019 | 17/6/2026 | Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to… | |
| Modificada | Media (5.4) | 0.76% | — | Firefly-iii Firefly III | 18/7/2019 | 17/6/2026 | Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability | |
| Modificada | Media (5.4) | 0.76% | — | Firefly-iii Firefly III | 18/7/2019 | 17/6/2026 | Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edit/$file_id$ attachment editing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to… | |
| Modificada | Media (5.4) | 0.76% | — | Firefly-iii Firefly III | 18/7/2019 | 17/6/2026 | Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$ tag summary page. NOTE: It is asserted that an attacker must have the same access rights as the user… | |
| Modificada | Media (5) | 11% | 💥 Exploit | Fireflymediaserver Firefly Media Server | 18/1/2013 | 16/6/2026 | Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2) Accept Language header, (3) User-agent header, (4) Host header, or (5) protocol version; or a (6) crafted HTTP… | |
| Modificada | Alta (7.5) | 3.7% | — | Fireflymediaserver | 16/4/2008 | 16/6/2026 | Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length. | |
| Modificada | Alta (7.5) | 3.7% | — | Firefly Media Server | 5/11/2007 | 16/6/2026 | Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the… | |
| Modificada | Alta (7.1) | 5.6% | 💥 Exploit | Firefly Media Server | 5/11/2007 | 16/6/2026 | webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers a crash in the ws_decodepassword function; or (2) a header line… | |
| Modificada | Alta (7.5) | 1.8% | — | Firefly | 2/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in modules/admin/include/config.php in FireFly 1.1.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 9.5% | 💥 Exploit | Firefly | 2/5/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/. | |
| Modificada | Media (5) | 1.7% | — | Firefly Studios Stronghold 2 | 30/5/2005 | 16/6/2026 | Firefly Studios Stronghold 2 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large size value for the nickname, which causes a memory allocation failure and generates an exception. |