Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.4% | — | Avira Antivir MailgateAvira Antivir Mailgate SuiteAvira Antivir PersonalAvira Antivir Sharepoint+6 | 12/2/2020 | 16/6/2026 | A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engine. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Unified Personal Communicator | 16/1/2020 | 16/6/2026 | Cisco Unified Personal Communicator 7.0 (1.13056) does not free allocated memory for received data and does not perform validation if memory allocation is successful, causing a remote denial of service condition. | |
| Modificada | Alta (8.8) | 1.0% | — | Najeebmedia Personalized Woocommerce Cart Page | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (5.4) | 0.64% | — | Personal Video Collection Script Project Personal Video Collection Script | 6/3/2019 | 17/6/2026 | PHP Scripts Mall Personal Video Collection Script 4.0.4 has Stored XSS via the "Update profile" feature. | |
| Modificada | Alta (7.5) | 3.5% | — | Seagate Personal Cloud Firmware | 28/4/2018 | 17/6/2026 | Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url. | |
| Modificada | Crítica (9.8) | 54% | 💥 Exploit | Seagate Personal Cloud Firmware | 12/1/2018 | 17/6/2026 | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled. | |
| Modificada | Alta (8.8) | 1.6% | — | Saat Personal | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in the installer of SaAT Personal ver.1.0.10.272 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (6.2) | 0.37% | — | IBM Personal Communications | 17/7/2016 | 17/6/2026 | IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script. | |
| Modificada | Alta (7.2) | 1.0% | 💥 Exploit | Softsphere Defensewall Personal Firewall | 19/2/2015 | 17/6/2026 | The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222000, 0x00222004, 0x00222008, 0x0022200c, or 0x00222010 IOCTL call. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | VLD Interactive Vldpersonals | 20/11/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search action to index.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | VLD Interactive Vldpersonals | 20/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a member_profile action to index.php. | |
| Modificada | Baja (2.1) | 0.54% | — | Eset Personal Firewall Ndis Filter | 4/11/2014 | 17/6/2026 | The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensitive information from kernel memory via crafted IOCTL calls. | |
| Modificada | Media (5.4) | 0.27% | — | 7 Habits Personal Development Project 7 Habits Personal Development | 21/10/2014 | 17/6/2026 | The 7 Habits Personal Development (aka appinventor.ai_ingka_d_jiw.TheCompleteGuideToApplyingThe7HabitsInHolisticPersonalDevelopment) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted… | |
| Modificada | Media (5.4) | 0.27% | — | Santanderbank Santander Personal Banking | 2/10/2014 | 17/6/2026 | The Santander Personal Banking (aka com.sovereign.santander) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Clubpersonal Club Personal | 9/9/2014 | 17/6/2026 | The Club Personal (aka com.globant.clubpersonal) application 2.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.2) | 0.39% | — | Infotecs Vipnet ClientInfotecs Vipnet CoordinatorInfotecs Vipnet Personal FirewallInfotecs Vipnet Safedisk | 22/5/2013 | 16/6/2026 | Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges… | |
| Modificada | Media (5.3) | 0.38% | — | Kingsoft Personal Firewall 9 | 25/8/2012 | 16/6/2026 | Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler… | |
| Modificada | Media (6.2) | 0.30% | — | Softsphere Defensewall Personal Firewall | 25/8/2012 | 16/6/2026 | Race condition in DefenseWall Personal Firewall 3.00 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution,… | |
| Modificada | Alta (7.5) | 1.3% | — | Uiga Personal Portal | 25/7/2012 | 16/6/2026 | SQL injection vulnerability in index2.php in Uiga Personal Portal allows remote attackers to execute arbitrary SQL commands via the p parameter. | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | IBM Personal Communications | 2/3/2012 | 16/6/2026 | Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote attackers to execute arbitrary code via a long profile string in a WorkStation (aka .ws) file. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1296. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1229. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1228. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1227. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1226. |