Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.4%—Avira Antivir MailgateAvira Antivir Mailgate SuiteAvira Antivir PersonalAvira Antivir Sharepoint+612/2/202016/6/2026
A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engine.
ModificadaAlta (7.5)1.3%—Cisco Unified Personal Communicator16/1/202016/6/2026
Cisco Unified Personal Communicator 7.0 (1.13056) does not free allocated memory for received data and does not perform validation if memory allocation is successful, causing a remote denial of service condition.
ModificadaAlta (8.8)1.0%—Najeebmedia Personalized Woocommerce Cart Page5/7/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (5.4)0.64%—Personal Video Collection Script Project Personal Video Collection Script6/3/201917/6/2026
PHP Scripts Mall Personal Video Collection Script 4.0.4 has Stored XSS via the "Update profile" feature.
ModificadaAlta (7.5)3.5%—Seagate Personal Cloud Firmware28/4/201817/6/2026
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.
ModificadaCrítica (9.8)54%💥 ExploitSeagate Personal Cloud Firmware12/1/201817/6/2026
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.
ModificadaAlta (8.8)1.6%—Saat Personal9/6/201717/6/2026
Untrusted search path vulnerability in the installer of SaAT Personal ver.1.0.10.272 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (6.2)0.37%—IBM Personal Communications17/7/201617/6/2026
IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script.
ModificadaAlta (7.2)1.0%💥 ExploitSoftsphere Defensewall Personal Firewall19/2/201517/6/2026
The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222000, 0x00222004, 0x00222008, 0x0022200c, or 0x00222010 IOCTL call.
ModificadaAlta (7.5)1.2%💥 ExploitVLD Interactive Vldpersonals20/11/201417/6/2026
Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search action to index.php.
ModificadaMedia (4.3)1.5%💥 ExploitVLD Interactive Vldpersonals20/11/201417/6/2026
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a member_profile action to index.php.
ModificadaBaja (2.1)0.54%—Eset Personal Firewall Ndis Filter4/11/201417/6/2026
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensitive information from kernel memory via crafted IOCTL calls.
ModificadaMedia (5.4)0.27%—7 Habits Personal Development Project 7 Habits Personal Development21/10/201417/6/2026
The 7 Habits Personal Development (aka appinventor.ai_ingka_d_jiw.TheCompleteGuideToApplyingThe7HabitsInHolisticPersonalDevelopment) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted…
ModificadaMedia (5.4)0.27%—Santanderbank Santander Personal Banking2/10/201417/6/2026
The Santander Personal Banking (aka com.sovereign.santander) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Clubpersonal Club Personal9/9/201417/6/2026
The Club Personal (aka com.globant.clubpersonal) application 2.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.2)0.39%—Infotecs Vipnet ClientInfotecs Vipnet CoordinatorInfotecs Vipnet Personal FirewallInfotecs Vipnet Safedisk22/5/201316/6/2026
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges…
ModificadaMedia (5.3)0.38%—Kingsoft Personal Firewall 925/8/201216/6/2026
Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (6.2)0.30%—Softsphere Defensewall Personal Firewall25/8/201216/6/2026
Race condition in DefenseWall Personal Firewall 3.00 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution,…
ModificadaAlta (7.5)1.3%—Uiga Personal Portal25/7/201216/6/2026
SQL injection vulnerability in index2.php in Uiga Personal Portal allows remote attackers to execute arbitrary SQL commands via the p parameter.
ModificadaAlta (9.3)37%💥 ExploitIBM Personal Communications2/3/201216/6/2026
Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote attackers to execute arbitrary code via a long profile string in a WorkStation (aka .ws) file.
ModificadaAlta (10)12%—HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension19/10/201116/6/2026
Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1296.
ModificadaAlta (10)12%—HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension19/10/201116/6/2026
Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1229.
ModificadaAlta (10)12%—HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension19/10/201116/6/2026
Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1228.
ModificadaAlta (10)12%—HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension19/10/201116/6/2026
Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1227.
ModificadaAlta (10)12%—HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension19/10/201116/6/2026
Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1226.
Orbitaley — Vulnerabilidades