Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 2.0% | — | Techotronic ALL IN ONE Favicon | 16/7/2018 | 17/6/2026 | Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text. | |
| Modificada | Baja (3.3) | 1.1% | — | Amazon Echo Show FirmwareAmazon Echo Plus FirmwareAmazon Echo DOT FirmwareAmazon Echo Spot Firmware+1 | 30/5/2018 | 17/6/2026 | Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an additional 8 seconds for input; if the user still does not respond, the… | |
| Modificada | Alta (7.8) | 0.34% | — | Echor Project Echor | 2/2/2018 | 17/6/2026 | The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login credentials by watching the process table. | |
| Modificada | Alta (7.8) | 0.41% | — | Echor Project Echor | 2/2/2018 | 17/6/2026 | The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password. | |
| Modificada | Media (5.4) | 0.51% | — | Typecho | 30/10/2017 | 17/6/2026 | In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/action/contents-post-edit. | |
| Modificada | Alta (7.8) | 1.2% | — | Enecho.meti Teikihoukokusho Sakuseishien Tool | 18/8/2017 | 17/6/2026 | Untrusted search path vulnerability in Teikihoukokusho Sakuseishien Tool v4.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.2% | — | Enecho.meti Shin Kinkyuji Houkoku Data Nyuryoku Program | 18/8/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer for Shin Kinkyuji Houkoku Data Nyuryoku Program (program released on 2011 March 10) Distributed on the website till 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.1% | — | Enecho.meti Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program | 18/8/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.2% | — | Enecho.meti Shin Kikan Toukei Houkoku Data Nyuryokuyou Program | 18/8/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer for Shin Kikan Toukei Houkoku Data Nyuryokuyou Program (program released on 2013 September 30) Distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (6.1) | 1.2% | — | Cpanel CgiechoCpanel Cgiemail | 3/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Cpanel CgiechoCpanel Cgiemail | 3/3/2017 | 17/6/2026 | cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location. | |
| Modificada | Alta (7.8) | 2.6% | — | Cpanel CgiechoCpanel Cgiemail | 3/3/2017 | 17/6/2026 | Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file. | |
| Modificada | Media (4) | 1.6% | — | Echo Project Echo | 9/11/2015 | 17/6/2026 | The Echo extension for MediWiki does not properly implement the hideuser functionality, which allows remote authenticated users to see hidden usernames in "non-revision based" notifications, as demonstrated by viewing a hidden username in a Thanks notification. | |
| Modificada | Media (5.4) | 0.27% | — | Echonewshk Echo News | 19/10/2014 | 17/6/2026 | The Echo News (aka com.solo.report) 1.10 application (beta) for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 3.5% | — | Echoping Project Echoping | 16/6/2014 | 16/6/2026 | Multiple buffer overflows in readline.c in Echoping 6.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted reply in the (1) TLS_readline or (2) SSL_readline function, related to the EchoPingHttps Smokeping probe. | |
| Modificada | Media (4.3) | 0.81% | — | Huawei Echo Life Hg8247 FirmwareHuawei Echo Life | 5/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML via an invalid TELNET connection attempt with a crafted username that is not properly handled during construction of the… | |
| Modificada | Media (5) | 9.9% | — | Nextapp Echo | 2/5/2013 | 16/6/2026 | The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Alta (7.5) | 1.5% | — | Tigran Abrahamyan Phpecho CMS | 24/8/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in kernel/smarty/Smarty.class.php in PHPEcho CMS 2.0 rc3 allows remote attackers to execute arbitrary PHP code via a URL in unspecified vectors that modify the _smarty_compile_path variable in the fetch function. | |
| Modificada | Alta (7.5) | 0.95% | — | Phpecho CMS | 9/7/2009 | 16/6/2026 | SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a thread action, a different vector than CVE-2008-0355. | |
| Modificada | Media (4.3) | 1.5% | — | Phpecho CMS | 9/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote attackers to inject arbitrary web script or HTML via a forum post. | |
| Modificada | Alta (7.5) | 2.7% | — | Echovnc | 19/8/2008 | 16/6/2026 | Stack-based buffer overflow in the CLogger::WriteFormated function in echoware/Logger.cpp in EchoVNC Linux before 1.1.2 allows remote echoServers to execute arbitrary code via a large (1) group or (2) user list, aka a "very crowded echoServer" attack. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (5) | 1.6% | — | Acronis True Image Echo Server | 13/8/2008 | 16/6/2026 | Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | — | Phpecho CMS | 18/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpecho CMS | 21/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in the admin panel in PHPEcho CMS before 1.6 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpecho CMS | 25/5/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in modules/admin/modules/gallery.php in PHPEcho CMS 2.0-rc1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter and possibly other parameters. NOTE: some of these details are obtained from third party information. |