Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.84% | — | Afnetworking Project Afnetworking | 27/10/2015 | 17/6/2026 | The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework before 2.5.3, as used in the ownCloud iOS Library, disables verification of a server hostname against the domain name in the subject's Common Name (CN) of the X.509 certificate, which allows… | |
| Modificada | Media (5) | 0.72% | — | Apple CfnetworkApple Safari | 21/7/2011 | 16/6/2026 | CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority. | |
| Modificada | Media (4.3) | 1.6% | — | Apple CfnetworkApple Safari | 21/7/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted text/plain file. | |
| Modificada | Alta (9.3) | 2.1% | — | Apple CfnetworkApple Safari | 21/7/2011 | 16/6/2026 | CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue. | |
| Modificada | Media (5) | 1.3% | — | Apple CfnetworkApple MAC OS XApple MAC OS X Server | 25/8/2010 | 16/6/2026 | CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Cyberfrogs Cfnetgs | 24/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in cyberfrogs.net cfnetgs 0.24 allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Ifnet Webif | 24/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/webif.exe in ifnet WebIf allows remote attackers to inject arbitrary web script or HTML via the cmd parameter. | |
| Modificada | Media (6.8) | 1.4% | — | Apple Cfnetwork | 3/8/2007 | 16/6/2026 | CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 does not properly validate ftp: URIs, which allows remote attackers to trigger the transmission of arbitrary FTP commands to arbitrary FTP servers. | |
| Modificada | Alta (9) | 7.9% | 💥 Exploit | Ifnet Webif.cgi | 19/6/2007 | 16/6/2026 | Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter. | |
| Modificada | Media (5) | 15% | 💥 Exploit | Cfnetwork | 30/1/2007 | 16/6/2026 | The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer dereference. | |
| Modificada | Media (4.6) | 0.69% | 💥 Exploit | Info Touch Surfnet | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command. | |
| Modificada | Baja (2.1) | 0.32% | — | Info Touch Surfnet KioskAI | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI. | |
| Modificada | Media (4.6) | 0.40% | — | Info Touch Surfnet | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts. |