Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Moneytree Project Moneytree | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for MoneyTree (TREE), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.0% | — | Supercoolawesomemoney Super Cool Awesome Money | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Super Cool Awesome Money (SCAM), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.0% | — | Moneychainnet Project Moneychainnet | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for MoneyChainNet (MCN), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Alta (7.5) | 0.99% | — | Moneytree Project Moneytree | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for MoneyTree (TREE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Crítica (9.8) | 1.4% | — | Cognito Moneyworks | 26/6/2017 | 17/6/2026 | Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file. | |
| Modificada | Media (5.5) | 1.7% | — | Moneyforward Money Forward FOR ApppassMoneyforward Money Forward FOR AU SmartpassMoneyforward Money Forward FOR Chou HoudaiMoneyforward Money Forward FOR SBI Sumishin NET Bank+6 | 12/5/2017 | 17/6/2026 | The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for SHIGA BANK (prior to v1.2.0), Money Forward for SHIZUOKA BANK (prior to v1.4.0), Money Forward for SBI Sumishin Net Bank (prior to v1.6.0), Money Forward for Tokai Tokyo Securities (prior to… | |
| Modificada | Alta (7.8) | 1.4% | — | Moneyforward Money Forward FOR ApppassMoneyforward Money Forward FOR AU SmartpassMoneyforward Money Forward FOR Chou HoudaiMoneyforward Money Forward FOR SBI Sumishin NET Bank+6 | 12/5/2017 | 17/6/2026 | The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for SHIGA BANK (prior to v1.2.0), Money Forward for SHIZUOKA BANK (prior to v1.4.0), Money Forward for SBI Sumishin Net Bank (prior to v1.6.0), Money Forward for Tokai Tokyo Securities (prior to… | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | Phpmoneybooks | 17/11/2014 | 16/6/2026 | Directory traversal vulnerability in index.php in phpMoneyBooks 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2012-1669. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Phpmoneybooks | 17/11/2014 | 16/6/2026 | Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Cnnmoney Portfolio FOR Stocks | 2/10/2014 | 17/6/2026 | The CNNMoney Portfolio for stocks (aka com.cnn.portfolio) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Youngmoney LIL Wayne Slots\ | 17/9/2014 | 17/6/2026 | The Lil Wayne Slots: FREE SLOTS (aka com.lilwayneslots.slots.android) application 1.138 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Cnnmoney Portfolio | 11/9/2014 | 17/6/2026 | The CNNMoney Portfolio (aka com.cnn.cnnmoney) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Makingmoneywithandroid Ingress Intel Helper | 9/9/2014 | 17/6/2026 | The Ingress Intel Helper (aka com.bb.ingressintel) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 0.57% | — | MoneybookersOscommerce | 4/11/2012 | 16/6/2026 | The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (4.3) | 8.4% | — | Microsoft Money | 2/1/2009 | 16/6/2026 | An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property. | |
| Modificada | Alta (7.5) | 5.8% | 💥 Exploit | Valusoft Chris Moneymakers World Poker Championship | 23/8/2005 | 16/6/2026 | Buffer overflow in Chris Moneymaker's World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Money | 20/10/2000 | 16/6/2026 | The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. |