Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.0% | — | Simple Download Monitor Project Simple Download Monitor | 4/1/2018 | 17/6/2026 | The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php. | |
| Modificada | Alta (8.1) | 1.6% | — | TOR Project TORDebian Linux | 3/12/2017 | 17/6/2026 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged in certain error cases, aka TROVE-2017-013. | |
| Modificada | Baja (3.7) | 0.90% | — | TOR Project TORDebian Linux | 3/12/2017 | 17/6/2026 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012. | |
| Modificada | Alta (7.5) | 2.0% | — | TOR Project TORDebian Linux | 3/12/2017 | 17/6/2026 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requiring a password, which triggers an attempt by the OpenSSL library to… | |
| Modificada | Alta (7.5) | 1.7% | — | TOR Project TORDebian Linux | 3/12/2017 | 17/6/2026 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010. | |
| Modificada | Alta (7.5) | 1.4% | — | TOR Project TORDebian Linux | 3/12/2017 | 17/6/2026 | In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send many INTRODUCE2 cells to trigger this issue. | |
| Modificada | Crítica (9.8) | 3.0% | — | Store Locator Project Store Locator | 16/10/2017 | 17/6/2026 | SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php. | |
| Modificada | Media (6.1) | 6.1% | 💥 Exploit | Bouqueteditor Project Bouqueteditor | 12/10/2017 | 17/6/2026 | There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI. | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | Usb-creator Project Usb-creator | 28/9/2017 | 17/6/2026 | usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method. | |
| Modificada | Media (6.1) | 0.85% | — | Django-epiceditor Project Django-epiceditor | 9/3/2017 | 17/6/2026 | There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field. | |
| Modificada | Media (6.1) | 0.68% | — | Epiceditor Project Epiceditor | 9/3/2017 | 17/6/2026 | EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document. | |
| Modificada | Media (6.1) | 3.2% | 💥 Exploit | Defa-online-image-protector Project Defa-online-image-protector | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin defa-online-image-protector v3.3 | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Admin-font-editor Project Admin-font-editor | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin admin-font-editor v1.8 | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Simple-image-manipulator Project Simple-image-manipulator | 6/10/2016 | 17/6/2026 | Remote file download in simple-image-manipulator v1.0 wordpress plugin | |
| Modificada | Media (4.3) | 1.9% | — | Mysql-lite-administrator Project Mysql-lite-administrator | 24/6/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite Administrator (mysql-lite-administrator) beta-1 allow remote attackers to inject arbitrary web script or HTML via the table_name parameter to (1) tabella.php, (2) coloni.php, or (3) insert.php or (4) num_row parameter to coloni.php. | |
| Modificada | Media (6.5) | 1.0% | — | Store Locator Project Store Locator | 16/6/2015 | 17/6/2026 | SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 0.64% | — | Campaign Monitor Project Campaign Monitor | 15/6/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in includes/campaignmonitor_lists.admin.inc in the Campaign Monitor module 7.x-1.0 for Drupal allow remote attackers to hijack the authentication of users for requests that (1) enable list subscriptions via a request to… | |
| Modificada | Media (6.8) | 0.64% | — | Watchdog Aggregator Project Watchdog Aggregator | 15/6/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Watchdog Aggregator module for Drupal allows remote attackers to hijack the authentication of administrators for requests that enable or disable monitoring sites via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Magicam Photo Magic Editor Project Magicam Photo Magic Editor | 21/10/2014 | 17/6/2026 | The Magicam Photo Magic Editor (aka mobi.magicam.editor) application 5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Funny Photo Color Editor Project Funny Photo Color Editor | 16/10/2014 | 17/6/2026 | The Funny Photo Color Editor (aka com.doirdeditor.funcloreditor) application 0.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Zombie Detector Project Zombie Detector | 22/9/2014 | 17/6/2026 | The Zombie Detector (aka com.jimmybolstad.zombiedetector) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Pocket CAM Photo Editor Project Pocket CAM Photo Editor | 22/9/2014 | 17/6/2026 | The Pocket Cam Photo Editor (aka mobi.pocketcam.editor) application 3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 7.9% | 💥 Exploit | Castor Project CastorOpensuseOpensuse Project Opensuse | 11/6/2014 | 17/6/2026 | The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document. | |
| Modificada | Media (6.5) | 0.92% | 💥 Exploit | Openconstructor Project Openconstructor | 28/12/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5) data/publication/edit.php, or (6)… | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Openconstructor Project Openconstructor | 28/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php. |