Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Narr8 Spin - Motion Comic | 19/10/2014 | 17/6/2026 | The SPIN - Motion Comic (aka me.narr8.android.serial.spin) application 2.1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Promotionalshop Promotional Items | 19/10/2014 | 17/6/2026 | The Promotional Items (aka com.wPromotionalItems) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Fbpromotions Project Fbpromotions | 1/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/swarm-settings.php in the Bugs Go Viral : Facebook Promotion Generator (fbpromotions) plugin 1.3.4 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) promo_type, (2) fb_edit_action, or (3) promo_id parameter. | |
| Modificada | Alta (9.3) | 2.3% | — | Softmotion3d SoftmotionFesto Cecx-x-m1 Modular Controller3s-software Codesys Runtime SystemFesto Cecx-x-c1 Modular Master Controller | 25/4/2014 | 17/6/2026 | The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log… | |
| Modificada | Alta (9.3) | 3.3% | — | 3s-software Codesys Runtime SystemFesto Cecx-x-c1 Modular Master ControllerSoftmotion3d SoftmotionFesto Cecx-x-m1 Modular Controller | 25/4/2014 | 17/6/2026 | The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code or cause a denial of service (application crash) via unspecified… | |
| Modificada | Media (5) | 4.9% | 💥 Exploit | Apple Motion | 4/11/2013 | 16/6/2026 | Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denial of service (application crash) via a (1) large or (2) small value in the subview attribute of a viewer element in a .motn file. | |
| Modificada | Media (4.3) | 1.5% | — | Rocomotion P BoardRocomotion P Diary RRocomotion P ForumRocomotion P Link+6 | 20/1/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM… | |
| Modificada | Media (5) | 1.6% | — | Rocomotion P Forum | 22/12/2009 | 16/6/2026 | Directory traversal vulnerability in Pforum.php in Rocomotion P forum before 1.28 allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors. | |
| Modificada | Media (6.8) | 0.99% | 💥 Exploit | Phpmotion | 20/4/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that modify an account via the (1) password or (2) email_address parameter. | |
| Modificada | Alta (9.3) | 19% | — | Research IN Motion Limited Blackberry Application WEB Loader | 10/2/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the Research in Motion RIM AxLoader ActiveX control in AxLoader.ocx and AxLoader.dll in BlackBerry Application Web Loader 1.0 allow remote attackers to execute arbitrary code via unspecified use of the (1) load or (2) loadJad method. | |
| Modificada | Alta (9.3) | 4.9% | — | Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite | 21/1/2009 | 16/6/2026 | The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to… | |
| Modificada | Alta (9.3) | 5.5% | — | Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite | 20/1/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via… | |
| Modificada | Media (6.5) | 3.3% | 💥 Exploit | Phpmotion | 10/7/2008 | 16/6/2026 | Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then accessing it via a direct request to the file under pictures/. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Phpmotion | 10/7/2008 | 16/6/2026 | SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter. | |
| Modificada | Alta (10) | 8.0% | — | Lavrsen Motion | 13/6/2008 | 16/6/2026 | Off-by-one error in the read_client function in webhttpd.c in Motion 3.2.10 and earlier might allow remote attackers to execute arbitrary code via a long request to a Motion HTTP Control interface, which triggers a stack-based buffer overflow with some combinations of processor architecture and compiler. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Pixel Motion Blog | 27/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter. | |
| Modificada | Alta (9) | 5.2% | 💥 Exploit | Pixel Motion Blog | 17/4/2008 | 16/6/2026 | admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Pixel Motion Blog | 17/4/2008 | 16/6/2026 | SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Pixel Motion Blog | 17/4/2008 | 16/6/2026 | admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information. | |
| Modificada | Media (6.4) | 7.4% | 💥 Exploit | Creamotion | 9/10/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in CMS Creamotion allow remote attackers to execute arbitrary PHP code via a URL in the cfg[document_uri] parameter to (1) _administration/securite.php and (2) _administration/gestion_configurations/save_config.php. | |
| Modificada | Baja (2.3) | 0.60% | — | Research IN Motion Limited Blackberry 7270 | 27/6/2007 | 16/6/2026 | The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered. | |
| Modificada | Baja (2.3) | 0.67% | — | Research IN Motion Limited Blackberry 7270 | 27/6/2007 | 16/6/2026 | Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers to cause a denial of service (blocked call reception and calling) via format string specifiers in an SIP INVITE message that lacks a host name in the Contact header. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Motionborg WEB Real Estate | 11/1/2007 | 16/6/2026 | SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. NOTE: some details were obtained from third party information. | |
| Modificada | Alta (7.5) | 47% | 💥 Exploit | Pixel Motion Blog | 29/9/2006 | 16/6/2026 | Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nom_blog parameter, which is injected into include/variables.php. | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | Pixel Motion Blog | 29/9/2006 | 16/6/2026 | Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not. |