Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.6% | — | Public Knowledge Project Open Monograph Press | 19/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in templates/frontend/pages/searchResults.tpl in Public Knowledge Project (PKP) Open Monograph Press (OMP) v1.2.0 through 3.1.1-2 before 3.1.1-3 allows remote attackers to inject arbitrary web script or HTML via the catalog.noTitlesSearch parameter (aka the Search field). | |
| Modificada | Crítica (9.8) | 3.5% | — | Mono-project MonoDebian Linux | 8/1/2018 | 17/6/2026 | The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. | |
| Modificada | Alta (7.5) | 3.2% | — | Mono-project Mono | 8/1/2018 | 17/6/2026 | The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204. | |
| Modificada | Alta (8.1) | 2.0% | — | Mono-project MonoDebian Linux | 8/1/2018 | 17/6/2026 | The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue. | |
| Modificada | Media (5.9) | 0.49% | — | Mononabank Middleton Community Bank Mobile | 16/6/2017 | 17/6/2026 | The "Middleton Community Bank Mobile Banking" by Middleton Community Bank app 3.0.0 -- aka middleton-community-bank-mobile-banking/id721843238 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted… | |
| Modificada | Media (6.8) | 0.95% | — | Arris NA Model 862 GW Mono Firmware | 21/11/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (4.3) | 1.2% | — | Arris NA Model 862 GW Mono Firmware | 21/11/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to inject arbitrary web script or HTML via the pwd parameter. | |
| Modificada | Alta (9.3) | 2.1% | — | Arris NA Model 862 GW Mono Firmware | 21/11/2015 | 17/6/2026 | Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded administrator password derived from a serial number, which makes it easier for remote attackers to obtain access via the web management interface, SSH, TELNET, or SNMP. | |
| Modificada | Media (4.3) | 2.5% | — | Arris NA Model 862 GW Mono Firmware | 21/11/2015 | 16/6/2026 | Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have predictable technician passwords, which makes it easier for remote attackers to obtain access via the web management interface, related to a "password of the day" issue. | |
| Modificada | Media (5) | 19% | 💥 Exploit | Dell Idrac6 ModularDell Idrac7Intel IpmiDell Idrac6 Monolithic | 19/12/2014 | 17/6/2026 | The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack. | |
| Modificada | Media (5.4) | 0.27% | — | Fermononrespiri Mobile | 29/9/2014 | 17/6/2026 | The Fermononrespiri Mobile (aka com.tapatalk.rmonlineitforums) application 3.8.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Dell Idrac6 FirmwareDell Idrac6 MonolithicDell Idrac7 FirmwareDell Idrac7 | 24/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Mono | 12/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an… | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Monoxide0184 Oxide Webserver | 8/12/2011 | 16/6/2026 | Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request. | |
| Modificada | Alta (7.5) | 1.5% | — | Mawashimono Nikki | 1/12/2011 | 16/6/2026 | Directory traversal vulnerability in HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to read and modify arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Mawashimono Nikki | 30/11/2011 | 16/6/2026 | HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability." | |
| Modificada | Media (5.8) | 2.7% | — | MonoNovell Moonlight | 13/4/2011 | 16/6/2026 | Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance. | |
| Modificada | Media (6.8) | 2.9% | — | MonoNovell Moonlight | 13/4/2011 | 16/6/2026 | Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to finalizing and then resurrecting a DynamicMethod instance. | |
| Modificada | Media (5.8) | 2.2% | — | MonoNovell Moonlight | 13/4/2011 | 16/6/2026 | Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service (plugin crash) or corrupt the internal… | |
| Modificada | Media (5.8) | 2.7% | — | MonoNovell Moonlight | 13/4/2011 | 16/6/2026 | The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which allows remote attackers to modify internal read-only data structures, and cause a denial of service (plugin crash) or corrupt the internal… | |
| Modificada | Media (5) | 1.5% | — | Mono | 11/1/2011 | 16/6/2026 | Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.NET) applications via unknown vectors related to an "unloading bug." | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | MonoNovell Moonlight | 6/12/2010 | 16/6/2026 | Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call. | |
| Modificada | Media (6.9) | 0.35% | — | Mono | 17/11/2010 | 16/6/2026 | Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Media (5) | 2.1% | — | Monotone | 27/10/2010 | 16/6/2026 | monotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command. | |
| Modificada | Media (6.9) | 0.39% | — | Debian Mono-debugger | 20/10/2010 | 16/6/2026 | The (1) mdb and (2) mdb-symbolreader scripts in mono-debugger 2.4.3, and other versions before 2.8.1, place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. |