Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.43% | — | Totalonlinesolutions Advanced Webhost Billing System | 8/1/2021 | 17/6/2026 | Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page. | |
| Modificada | Alta (7.8) | 0.47% | — | Bbraun Onlinesuite Application Package | 6/11/2020 | 17/6/2026 | A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute code on the system as a high privileged user. | |
| Modificada | Crítica (9.8) | 2.0% | — | Bbraun Onlinesuite Application Package | 6/11/2020 | 17/6/2026 | A relative path traversal attack in the B. Braun OnlineSuite Version AP 3.0 and earlier allows unauthenticated attackers to upload or download arbitrary files. | |
| Modificada | Alta (7.8) | 0.98% | — | Bbraun Onlinesuite Application Package | 6/11/2020 | 17/6/2026 | An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (8.8) | 0.78% | — | Pagelines | 13/9/2019 | 17/6/2026 | The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF. | |
| Modificada | Alta (7.5) | 6.6% | — | Microsoft .net CoreMicrosoft Asp.net CoreMicrosoft System.io.pipelines | 13/9/2018 | 17/6/2026 | A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. | |
| Modificada | Media (5.4) | 0.27% | — | Pegasus Airlines Project Pegasus Airlines | 21/10/2014 | 17/6/2026 | The Pegasus Airlines (aka com.wPegasusAirlines) application 0.84.13503.96707 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Headlines News India Project Headlines News India | 20/10/2014 | 17/6/2026 | The Headlines news India (aka com.dreamstep.wHEADLINESNEWSINDIA) application 0.21.13219.95110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Iata Airlines International | 25/9/2014 | 17/6/2026 | The Airlines International (aka org.iata.IAMagazine) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.3% | — | Sabreairlinesolutions Crew ManagementSabreairlinesolutions Crew OperationsSabreairlinesolutions Crew PlanningSabreairlinesolutions Crew Services+1 | 26/7/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Epic Games Unreal TournamentFrontlines Fuel OF WAR | 19/8/2009 | 16/6/2026 | Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Xlinesoft Phprunner | 19/3/2009 | 16/6/2026 | UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Xlinesoft Phprunner | 19/3/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Rightscripts Text Lines Rearrange Script | 27/2/2009 | 16/6/2026 | Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled, allows remote attackers to read arbitrary local files via directory traversal sequences in the filename parameter. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Elinestudio Site Composer | 25/6/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Elinestudio Site Composer | 25/6/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4) txtEmail parameters to login.asp. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Elinestudio Site Composer | 25/6/2008 | 16/6/2026 | Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Elinestudio Site Composer | 25/6/2008 | 16/6/2026 | eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2) common2.asp in cms/include/, which reveals the database path. | |
| Modificada | Media (4.3) | 1.0% | — | Geek-palace.com Lineshout | 20/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Cardinal CMS Project Cardinal CMSRedlinesoft Lanai CMSSitex CMS Project Sitex CMSSyntax CMS Project Syntax CMS | 1/10/2007 | 16/6/2026 | Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown… | |
| Modificada | Baja (2.1) | 0.33% | — | Xlinesoft Phprunner | 17/11/2006 | 16/6/2026 | XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Phpnuke Myheadlines | 6/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the myh_op parameter to modules.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Ectools OnlineshopAI | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters. | |
| Modificada | Media (5) | 1.8% | — | Xlinesoft Asprunner | 31/12/2004 | 16/6/2026 | ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages. |