Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Differencegames Hidden Object - Alice Free | 9/9/2014 | 17/6/2026 | The Hidden Object - Alice Free (aka air.com.differencegames.hovisionsofalicefree) application 1.0.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Differencegames Hidden Memory - Aladdin Free! | 9/9/2014 | 17/6/2026 | The Hidden Memory - Aladdin FREE! (aka air.com.differencegames.hmaladdinfree) application 1.0.31 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.9) | 0.40% | — | Altova Diffdog 2011 | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Altova DiffDog 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .dbdif file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 3.5% | — | Rdiffweb | 17/5/2007 | 16/6/2026 | Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI. | |
| Modificada | Alta (7.5) | 2.3% | — | Rediff Toolbar | 10/3/2007 | 16/6/2026 | The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via unspecified manipulations, possibly involving improper initialization or blank arguments. | |
| Modificada | Alta (7.5) | 2.5% | — | Rediff BOL Downloader Activex OCX Control | 31/12/2006 | 16/6/2026 | Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter. | |
| Modificada | Media (4.6) | 0.38% | — | Tkdiff | 27/12/2005 | 16/6/2026 | tkdiff before 4.1.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (10) | 1.5% | — | Ldapdiff | 22/11/2005 | 16/6/2026 | Unspecified vulnerability in ldapdiff before 1.1.1 has unknown impact and attack vectors, related to "ldapdiff.conf path construction". | |
| Modificada | Baja (2.1) | 0.34% | — | Rogers Software Source Mgdiff Patch Viewer | 27/10/2005 | 16/6/2026 | viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Media (5) | 1.3% | — | Rediff BOLAI | 8/9/2005 | 16/6/2026 | The Fetch.FetchContact.1 ActiveX control (Fetch.dll) for Rediff Bol 7.0 allows remote attackers to read the Windows Address Book via the FullAddressBook method. |