Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9) | 0.42% | — | Google Nest CAM IQ Indoor Firmware | 20/8/2019 | 17/6/2026 | An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker can send specially… | |
| Modificada | Media (5.3) | 0.60% | — | Google Nest CAM IQ Indoor Firmware | 20/8/2019 | 17/6/2026 | An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of bounds read, resulting in information disclosure. An attacker can send packets to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.78% | — | Openweave-coreGoogle Nest CAM IQ Indoor Firmware | 20/8/2019 | 17/6/2026 | An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially crafted weave packet can cause an integer overflow to occur, resulting in PacketBuffer data reuse. An attacker can send a packet to trigger… | |
| Modificada | Alta (7.5) | 0.57% | — | Google Nest CAM IQ Indoor Firmware | 20/8/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can… | |
| Modificada | Alta (7.3) | 0.85% | 💥 Exploit | Pronestor Health Monitoring | 1/4/2019 | 17/6/2026 | The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse… | |
| Modificada | Alta (7.8) | 3.2% | — | EMC RSA Certificate ManagerEMC RSA Onestep | 2/10/2015 | 17/6/2026 | Directory traversal vulnerability in EMC RSA OneStep 6.9 before build 559, as used in RSA Certificate Manager and RSA Registration Manager through 6.9 build 558 and other products, allows remote attackers to read arbitrary files via a crafted KCSOSC_ERROR_PAGE parameter. | |
| Modificada | Media (5.4) | 0.29% | — | Nestler Ultimate Christian Radios | 21/10/2014 | 17/6/2026 | The Ultimate Christian Radios (aka com.ngg.ultimatechristianradios) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (2.1) | 0.94% | — | Nestor Mata Cuthbert Taxonomy Navigator | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Onestopjoomla COM Tupinambis | 28/9/2009 | 16/6/2026 | SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Freewebscriptz Honest Traffic | 16/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Elinestudio Site Composer | 25/6/2008 | 16/6/2026 | eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2) common2.asp in cms/include/, which reveals the database path. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Elinestudio Site Composer | 25/6/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Elinestudio Site Composer | 25/6/2008 | 16/6/2026 | Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Elinestudio Site Composer | 25/6/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4) txtEmail parameters to login.asp. | |
| Modificada | Alta (10) | 5.2% | — | Fenestrae Faxination Server | 9/8/2006 | 16/6/2026 | Unspecified vulnerability in Fenestrae Faxination Server allows remote attackers to execute arbitrary code via a crafted packet. |