Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.24% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+173 | 10/4/2019 | 17/6/2026 | In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo… | |
| Modificada | Media (6.1) | 4.4% | 💥 Exploit | Freshrss | 30/1/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter. | |
| Modificada | Media (5.4) | 0.83% | — | Freshdns Project Freshdns | 20/12/2018 | 17/6/2026 | FreshDNS version 1.0.3 and prior contains a Cross Site Scripting (XSS) vulnerability in Account data form; Zone editor that can result in Execution of attacker's JavaScript code in victim's session. This attack appear to be exploitable via The attacker stores a specially crafted string as their Full Name in their… | |
| Modificada | Alta (8.8) | 0.62% | — | Freshdns Project Freshdns | 20/12/2018 | 17/6/2026 | FreshDNS version 1.0.3 and earlier contains a Cross ite Request Forgery (CSRF) vulnerability in All (authenticated) API calls in index.php / class.manager.php that can result in Editing domains and zones with victim's privileges. This attack appear to be exploitable via Victim must open a website containing attacker's… | |
| Modificada | Alta (7.5) | 1.6% | — | Fresh Project Fresh | 7/6/2018 | 17/6/2026 | Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition. | |
| Modificada | Alta (8.8) | 1.1% | — | Fresh-media Brute Force Login Protection | 6/4/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that have unknown impact via a crafted request to the brute-force-login-protection page to wp-admin/options-general.php. | |
| Modificada | Media (5.4) | 0.27% | — | Home Made AIR Freshener Project Home Made AIR Freshener | 21/10/2014 | 17/6/2026 | The Home Made Air Freshener (aka com.wHomeMadeAirFreshener) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Freshdirect | 22/9/2014 | 17/6/2026 | The FreshDirect (aka com.freshdirect.android) application 2.7.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Freshplanet Songpop | 9/9/2014 | 17/6/2026 | The SongPop (aka air.com.freshplanet.games.WaM) application 1.21.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (2.1) | 0.96% | — | Devsaran Fresh | 27/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Fresh theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 1.6% | — | Freshwebmaster Fresh FTP | 2/11/2010 | 16/6/2026 | Directory traversal vulnerability in FreshWebMaster Fresh FTP 5.36, 5.37, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Freshscripts Fresh Email Script | 24/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to inject arbitrary web script or HTML via the Email parameter. NOTE: this can be leveraged to modify cookies and conduct session fixation attacks. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Freshscripts Fresh Email Script | 24/8/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the tmp_sid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Php-fusion Freshlinks Module | 14/11/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the linkid parameter. | |
| Modificada | Alta (7.2) | 0.37% | — | Freshmeat Xwine | 4/3/2008 | 16/6/2026 | w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.2) | 0.72% | 💥 Exploit | Freshmeat Generic Software Wrappers Toolkit | 13/8/2007 | 16/6/2026 | Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users to defeat system call interposition and possibly gain privileges or bypass auditing. | |
| Modificada | Alta (9.3) | 6.7% | 💥 Exploit | Freshdevices Freshview | 26/4/2007 | 16/6/2026 | Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. | |
| Modificada | Media (6.8) | 1.4% | — | Freshreader | 19/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to tag attributes. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | WEB Fresh Fresh Guest Book | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field. | |
| Modificada | Media (4.3) | 1.2% | — | Freshmeat Network Query Tool | 23/4/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to inject arbitrary web script or HTML via the portNum parameter. | |
| Modificada | Media (5) | 1.5% | — | Freshmeat Network Query ToolAI | 23/4/2004 | 16/6/2026 | nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to obtain sensitive information via a string in the portNum parameter, which reveals the full path in an error message. | |
| Modificada | Alta (7.5) | 2.1% | — | Freshmeat Network Query ToolFreshmeat Network Query Tool Phpnuke | 31/12/2001 | 16/6/2026 | network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter. |