Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.47%—Sync Oxygen Publishing EngineSync Oxygen XML AuthorSync Oxygen XML DeveloperSync Oxygen XML Editor+113/7/202217/6/2026
An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp…
ModificadaAlta (7.5)1.2%—Facebook MvfstFacebook Proxygen15/3/202117/6/2026
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a connection error. This issue affects mvfst versions prior to commit…
ModificadaCrítica (9.8)1.1%—Facebook Proxygen18/5/202017/6/2026
A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in a specific sequence. This issue affects versions of proxygen prior to v2020.05.18.00.
ModificadaAlta (7.5)1.1%—Sync Oxygen XML AuthorSync Oxygen XML DeveloperSync Oxygen XML Editor16/3/202017/6/2026
Oxygen XML Editor 21.1.1 allows XXE to read any file.
ModificadaCrítica (9.8)1.4%—Facebook Proxygen4/12/201917/6/2026
In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Proxygen from v0.29.0 until v2017.04.03.00.
ModificadaCrítica (9.8)2.1%—Facebook Proxygen25/7/201917/6/2026
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.
ModificadaMedia (6.1)1.8%—Doxygen24/5/201917/6/2026
Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.
ModificadaAlta (7.5)1.4%—Proxygen Project Proxygen31/12/201817/6/2026
An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00.
ModificadaAlta (7.5)1.4%—Proxygen Project Proxygen31/12/201817/6/2026
A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00.
ModificadaAlta (7.5)0.83%—Facebook Proxygen31/12/201817/6/2026
Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.
ModificadaMedia (6.8)0.34%—Oneplus Oxygenos29/3/201817/6/2026
An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android…
ModificadaMedia (5.9)0.45%—Oneplus Oxygenos11/5/201717/6/2026
An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the same OTA verification keys, and the fact that both products share the same 'ro.build.product' system property, attackers can install OTAs of one product over…
ModificadaMedia (5.9)0.43%—Oneplus Oxygenos11/5/201717/6/2026
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the same OTA verification keys, attackers can install HydrogenOS over OxygenOS and vice versa, even on locked bootloaders, which allows for exploitation of…
ModificadaMedia (5.9)0.76%—Oneplus Oxygenos11/5/201717/6/2026
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater-script' in OTAs that does not check that the current version is lower than or equal to the given image's. Downgrades can occur even on locked bootloaders and…
ModificadaAlta (7.5)1.1%—Oneplus Oxygenos11/5/201717/6/2026
An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the attack surface, and allows for remote exploitation of other…
ModificadaMedia (4.6)0.34%—Oneplus Oxygenos25/4/201717/6/2026
In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot oem dump <partition>' fastboot command.
ModificadaAlta (7.5)1.2%—Proxygen Project Proxygen10/4/201717/6/2026
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.
ModificadaCrítica (9.8)1.2%—Proxygen Project Proxygen10/4/201717/6/2026
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.
ModificadaAlta (7.5)1.2%—Proxygen Project Proxygen10/4/201717/6/2026
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.
ModificadaMedia (5.9)0.31%—Oneplus Oxygenos26/3/201717/6/2026
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or…
ModificadaMedia (6.6)0.37%—Oneplus Oxygenos19/3/201717/6/2026
An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command' in contradiction to the threat model of Android where the bootloader MUST NOT allow any security-sensitive operation to…
ModificadaCrítica (9.8)2.8%—Oneplus Oxygenos12/3/201717/6/2026
OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to lock/unlock the bootloader, disregarding the 'OEM Unlocking' checkbox, without user confirmation and without a factory reset. This allows for persistent code execution with high…
ModificadaCrítica (9.8)2.7%—Oneplus Oxygenos12/3/201717/6/2026
An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-verity disabled, by issuing the 'fastboot oem disable_dm_verity' command. Having dm-verity disabled, the kernel will not verify the system partition (and any…
ModificadaAlta (8.1)3.0%—Oneplus Oxygenos23/1/201717/6/2026
An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authentication. A physical attacker can press the "Volume Up" button during device boot, where an attacker with ADB access can issue the adb reboot…
ModificadaAlta (7.5)1.1%—O2php Oxygen Bulletin Board28/10/200816/6/2026
SQL injection vulnerability in member.php in Oxygen Bulletin Board 1.1.3 allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Orbitaley — Vulnerabilidades