Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.7)1.7%—Vega Project Vega30/12/202017/6/2026
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript…
ModificadaMedia (4.3)1.1%—Vega Project Vega9/3/202017/6/2026
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
ModificadaAlta (7.5)2.4%—Davegamble CjsonOracle Timesten In-memory Database19/7/201917/6/2026
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later.
ModificadaMedia (6.1)1.1%—Vegadesign Profiledesign CMS13/5/201917/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid, (6) cat, or (7) orderby parameter.
ModificadaCrítica (9.8)2.6%—Davegamble CjsonOracle Timesten In-memory Database9/5/201917/6/2026
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
ModificadaCrítica (9.8)2.5%—Davegamble CjsonOracle Timesten In-memory Database9/5/201917/6/2026
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
ModificadaCrítica (9.8)2.5%—Davegamble Cjson29/4/201917/6/2026
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
ModificadaCrítica (9.8)1.8%—Davegamble Cjson20/8/201817/6/2026
Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses cJSON library. If application provides network interface then can be…
ModificadaAlta (8.8)1.5%—Davegamble Cjson20/8/201817/6/2026
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or…
ModificadaAlta (7.5)1.7%—Davegamble Cjson20/8/201817/6/2026
Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to be exploitable via If the attacker can force the data to be printed and the system is in low memory it can force a leak of memory. This vulnerability appears…
ModificadaCrítica (9.8)1.8%—Sangoma Netborder/vega Session Firmware7/12/201717/6/2026
Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface.
ModificadaMedia (5.4)0.30%—Ilovegame Longjiang9/9/201417/6/2026
The longjiang (aka com.longjiang.kr) application 2.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Androkera LAS Vegas Lottery Scratch OFF9/9/201417/6/2026
The Las Vegas Lottery Scratch Off (aka com.androkera.lottery) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaBaja (2.6)0.95%—Bill Shupp Vegadns13/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Vegadns 0.99 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
ModificadaAlta (7.5)1.2%💥 ExploitBill Shupp Vegadns13/4/200616/6/2026
SQL injection vulnerability in index.php in Vegadns 0.99 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (7.5)1.4%—Johnny Vegas Vegas Forum7/3/200616/6/2026
SQL injection vulnerability in forumlib.php in Johnny_Vegas Vegas Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
ModificadaMedia (4.3)1.3%—Vegadns17/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the message parameter.
ModificadaMedia (5)1.6%—Vegadns17/8/200516/6/2026
index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.
Orbitaley — Vulnerabilidades