Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.6% | — | Projectsend | 20/4/2019 | 17/6/2026 | An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code. | |
| Modificada | Crítica (9.8) | 2.6% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Cp5525 FirmwareHP Color Laserjet Enterprise M553 FirmwareHP Color Laserjet Enterprise M552 Firmware+139 | 11/4/2019 | 17/6/2026 | HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code. | |
| Modificada | Crítica (9.8) | 2.6% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Cp5525 FirmwareHP Color Laserjet Enterprise Flow MFP M681f FirmwareHP Color Laserjet Enterprise Flow MFP M681z Firmware+134 | 27/3/2019 | 17/6/2026 | In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code. | |
| Modificada | Crítica (9.8) | 1.5% | — | Projectsend | 29/10/2018 | 17/6/2026 | ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | Projectsend | 29/10/2018 | 17/6/2026 | ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string. | |
| Modificada | Crítica (9.8) | 1.9% | — | Projectsend | 29/10/2018 | 17/6/2026 | ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Projectsend | 29/10/2018 | 17/6/2026 | ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter… | |
| Modificada | Alta (7.5) | 1.0% | — | Sendme Project Sendme | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for SendMe, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (6.1) | 1.0% | — | Projectsend | 6/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in My account Name updated, related to home.php and actions-log.php. | |
| Modificada | Media (6.1) | 1.1% | — | Projectsend | 6/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a Site name updated. | |
| Modificada | Alta (7.5) | 1.4% | — | Sendio | 27/7/2017 | 17/6/2026 | Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read potentially sensitive system files via a specially crafted URL. | |
| Modificada | Crítica (9.8) | 1.6% | — | Projectsend | 18/6/2017 | 17/6/2026 | install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Media (6.2) | 1.0% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective. | |
| Modificada | Alta (7.5) | 1.8% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access control of the request which could result in an attacker being able to shutdown the system. | |
| Modificada | Crítica (9.8) | 2.4% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands. | |
| Modificada | Media (5.3) | 4.7% | — | Send Project Send | 23/1/2017 | 17/6/2026 | The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors. | |
| Modificada | Media (4) | 5.4% | 💥 Exploit | Sendio | 2/6/2015 | 17/6/2026 | The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users' sessions via a large number of requests. | |
| Modificada | Media (5) | 6.6% | 💥 Exploit | Sendio | 2/6/2015 | 17/6/2026 | Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header. | |
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Projectsend | 20/3/2015 | 17/6/2026 | SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to users-edit.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Sendy | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Sendy | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Projectsend | 8/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the Description field in a file upload. NOTE: this issue was originally incorrectly mapped to CVE-2014-1155; see CVE-2014-1155 for more information. | |
| Modificada | Alta (7.5) | 43% | 💥 Exploit | Projectsend | 7/1/2015 | 17/6/2026 | Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in the upload/files/ or upload/temp/ directory. | |
| Modificada | Media (6.4) | 1.2% | — | Kofax E-transactions Sender Sendbox | 1/1/2015 | 16/6/2026 | The SaveMessage method in the LEADeMail.LEADSmtp.20 ActiveX control in LTCML14n.dll 14.0.0.34 in Kofax e-Transactions Sender Sendbox 2.5.0.933 allows remote attackers to write to arbitrary files via a pathname in the first argument. |