Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.99% | — | Statusnet | 12/11/2019 | 16/6/2026 | statusnet before 0.9.9 has XSS | |
| Modificada | Media (4.8) | 1.0% | — | Status301 Easy Fancybox | 26/9/2019 | 17/6/2026 | The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter. | |
| Modificada | Media (6.1) | 0.84% | — | Status Board Project Status Board | 26/8/2019 | 17/6/2026 | Status Board 1.1.81 has reflected XSS via dashboard.ts. | |
| Modificada | Media (6.1) | 0.84% | — | Status Board Project Status Board | 26/8/2019 | 17/6/2026 | Status Board 1.1.81 has reflected XSS via logic.ts. | |
| Modificada | Crítica (9.8) | 4.1% | — | Status React Native Desktop | 23/7/2019 | 17/6/2026 | ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution. | |
| Modificada | Media (6.1) | 1.7% | — | Jenkins Embeddable Build Status | 11/7/2019 | 17/6/2026 | A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin. | |
| Modificada | Alta (8.8) | 1.7% | — | Xpertsol Server Status BY Hostname/ip | 3/7/2019 | 17/6/2026 | A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an authenticated user to execute arbitrary SQL commands via GET parameters. | |
| Modificada | Media (5) | 5.5% | 💥 Exploit | Status2k | 20/10/2014 | 17/6/2026 | Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function. | |
| Modificada | Media (5.4) | 0.27% | — | Statusvia Facebook Status VIA | 18/9/2014 | 17/6/2026 | The Facebook Status Via (aka com.StatusViaAdvanced) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.5) | 2.8% | 💥 Exploit | Status2k | 6/8/2014 | 17/6/2026 | admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Status2k | 6/8/2014 | 17/6/2026 | SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Status2k | 6/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Statusnet | 11/10/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format." | |
| Modificada | Alta (7.1) | 1.8% | — | ATT StatusHTC ChachaHTC DesireHTC Merge+5 | 21/8/2012 | 16/6/2026 | The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain… | |
| Modificada | Media (5) | 1.2% | — | 53x11 WOW Server Status | 24/9/2011 | 16/6/2026 | WoW Server Status 4.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by status.php and certain other files. | |
| Modificada | Media (5) | 1.2% | — | Statusnet | 24/9/2011 | 16/6/2026 | StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files. | |
| Modificada | Media (5) | 14% | 💥 Exploit | Joomlamo COM Userstatus | 8/4/2010 | 16/6/2026 | Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Baja (3.6) | 2.3% | 💥 Exploit | Plutostatus Locator | 19/2/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Hinton Design Phpstatus | 7/2/2006 | 16/6/2026 | phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authentication. | |
| Modificada | Alta (7.5) | 1.4% | — | Hinton Design Phpstatus | 7/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the username parameter in check.php and (2) unknown attack vectors in the administrative interface. | |
| Modificada | Media (4.3) | 1.3% | — | Hinton Design Phpstatus | 7/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface. |