Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.83% | — | Siren Federate | 13/4/2021 | 17/6/2026 | Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10.x before 7.10.2-22.2, and 7.11.x before 7.11.2-23.0 can leak user information across thread contexts. This occurs in opportunistic circumstances when there is concurrent query execution by a… | |
| Modificada | Media (5.4) | 0.27% | — | Desire2learn Fusion 2014 Project Desire2learn Fusion 2014 | 19/10/2014 | 17/6/2026 | The Desire2Learn FUSION 2014 (aka com.desire2learn.fusion2012) application 4.0.729.1748 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.1) | 1.8% | — | ATT StatusHTC ChachaHTC DesireHTC Merge+5 | 21/8/2012 | 16/6/2026 | The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain… | |
| Modificada | Baja (2.6) | 1.3% | — | HTC Desire HDHTC Desire SHTC Droid IncredibleHTC EVO 3D+5 | 5/2/2012 | 16/6/2026 | Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that… | |
| Modificada | Alta (7.5) | 1.7% | — | Hubert Plisson Sire | 11/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in lire.php in Sire 2.0 nws allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Hubert Plisson Sire | 11/4/2006 | 16/6/2026 | Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php. |