Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)1.0%—Simple Download Monitor Project Simple Download Monitor4/1/201817/6/2026
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
ModificadaAlta (8.1)1.6%—TOR Project TORDebian Linux3/12/201717/6/2026
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged in certain error cases, aka TROVE-2017-013.
ModificadaBaja (3.7)0.90%—TOR Project TORDebian Linux3/12/201717/6/2026
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
ModificadaAlta (7.5)2.0%—TOR Project TORDebian Linux3/12/201717/6/2026
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requiring a password, which triggers an attempt by the OpenSSL library to…
ModificadaAlta (7.5)1.7%—TOR Project TORDebian Linux3/12/201717/6/2026
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010.
ModificadaAlta (7.5)1.4%—TOR Project TORDebian Linux3/12/201717/6/2026
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send many INTRODUCE2 cells to trigger this issue.
ModificadaCrítica (9.8)3.0%—Store Locator Project Store Locator16/10/201717/6/2026
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.
ModificadaMedia (6.1)6.1%💥 ExploitBouqueteditor Project Bouqueteditor12/10/201717/6/2026
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.
ModificadaAlta (7.8)1.5%💥 ExploitUsb-creator Project Usb-creator28/9/201717/6/2026
usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method.
ModificadaMedia (6.1)0.85%—Django-epiceditor Project Django-epiceditor9/3/201717/6/2026
There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.
ModificadaMedia (6.1)0.68%—Epiceditor Project Epiceditor9/3/201717/6/2026
EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.
ModificadaMedia (6.1)3.2%💥 ExploitDefa-online-image-protector Project Defa-online-image-protector10/10/201617/6/2026
Reflected XSS in wordpress plugin defa-online-image-protector v3.3
ModificadaMedia (6.1)3.7%💥 ExploitAdmin-font-editor Project Admin-font-editor10/10/201617/6/2026
Reflected XSS in wordpress plugin admin-font-editor v1.8
ModificadaAlta (7.5)6.9%💥 ExploitSimple-image-manipulator Project Simple-image-manipulator6/10/201617/6/2026
Remote file download in simple-image-manipulator v1.0 wordpress plugin
ModificadaMedia (4.3)1.9%—Mysql-lite-administrator Project Mysql-lite-administrator24/6/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite Administrator (mysql-lite-administrator) beta-1 allow remote attackers to inject arbitrary web script or HTML via the table_name parameter to (1) tabella.php, (2) coloni.php, or (3) insert.php or (4) num_row parameter to coloni.php.
ModificadaMedia (6.5)1.0%—Store Locator Project Store Locator16/6/201517/6/2026
SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.8)0.64%—Campaign Monitor Project Campaign Monitor15/6/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in includes/campaignmonitor_lists.admin.inc in the Campaign Monitor module 7.x-1.0 for Drupal allow remote attackers to hijack the authentication of users for requests that (1) enable list subscriptions via a request to…
ModificadaMedia (6.8)0.64%—Watchdog Aggregator Project Watchdog Aggregator15/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Watchdog Aggregator module for Drupal allows remote attackers to hijack the authentication of administrators for requests that enable or disable monitoring sites via unspecified vectors.
ModificadaMedia (5.4)0.27%—Magicam Photo Magic Editor Project Magicam Photo Magic Editor21/10/201417/6/2026
The Magicam Photo Magic Editor (aka mobi.magicam.editor) application 5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Funny Photo Color Editor Project Funny Photo Color Editor16/10/201417/6/2026
The Funny Photo Color Editor (aka com.doirdeditor.funcloreditor) application 0.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Zombie Detector Project Zombie Detector22/9/201417/6/2026
The Zombie Detector (aka com.jimmybolstad.zombiedetector) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Pocket CAM Photo Editor Project Pocket CAM Photo Editor22/9/201417/6/2026
The Pocket Cam Photo Editor (aka mobi.pocketcam.editor) application 3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)7.9%💥 ExploitCastor Project CastorOpensuseOpensuse Project Opensuse11/6/201417/6/2026
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.
ModificadaMedia (6.5)0.92%💥 ExploitOpenconstructor Project Openconstructor28/12/201216/6/2026
Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5) data/publication/edit.php, or (6)…
ModificadaMedia (4.3)1.4%💥 ExploitOpenconstructor Project Openconstructor28/12/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.
Orbitaley — Vulnerabilidades