Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.83% | — | Gforge Advanced Server | 25/3/2019 | 17/6/2026 | GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring. | |
| Modificada | Alta (7.8) | 1.2% | — | Pdfforge PDF Architect | 10/11/2018 | 17/6/2026 | Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of a "Data from Faulting Address controls Code Flow" issue. | |
| Modificada | Media (6.5) | 0.86% | — | Forgerock Access Management | 21/2/2018 | 17/6/2026 | The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file. | |
| Modificada | Media (6.1) | 2.4% | — | Oxidforge Eshop | 18/1/2018 | 17/6/2026 | CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks… | |
| Modificada | Alta (8.8) | 1.8% | — | Fontforge | 14/12/2017 | 17/6/2026 | uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534. | |
| Modificada | Alta (7.8) | 1.1% | — | Lhaforge Project Lhaforge | 2/8/2017 | 17/6/2026 | Untrusted search path vulnerability in LhaForge Ver.1.6.5 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.2% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file. | |
| Modificada | Media (5.5) | 0.71% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 does not ensure a positive size in a weight vector memcpy call in readcfftopdict (parsettf.c) resulting in DoS via a crafted otf file. | |
| Modificada | Alta (7.8) | 1.2% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parsettf.c. | |
| Modificada | Alta (7.8) | 1.4% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted otf file. | |
| Modificada | Alta (7.8) | 1.2% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file. | |
| Modificada | Alta (7.8) | 1.2% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file. | |
| Modificada | Alta (7.8) | 1.5% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file. | |
| Modificada | Alta (7.8) | 1.4% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file. | |
| Modificada | Alta (7.8) | 1.4% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file. | |
| Modificada | Alta (7.8) | 1.4% | — | Fontforge | 23/7/2017 | 17/6/2026 | FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file. | |
| Modificada | Alta (8.8) | 1.9% | — | Oxidforge Oxid Eshop | 10/4/2017 | 17/6/2026 | OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professional Edition v4.9.9, Community Edition v4.8.12, Community Edition v4.9.9. | |
| Modificada | Alta (8.1) | 2.3% | — | Forgerock Racf Connector | 3/2/2017 | 17/6/2026 | Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning. | |
| Modificada | Alta (7.5) | 2.5% | — | Forgerock Openam | 2/1/2017 | 17/6/2026 | XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter. | |
| Modificada | Media (6.1) | 3.4% | — | Designsandcode Forget About Shortcode Buttons | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin forget-about-shortcode-buttons v1.1.1 | |
| Modificada | Alta (10) | 4.5% | — | Fusionforge | 2/6/2015 | 17/6/2026 | The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parameter when creating a secondary Git repository. | |
| Modificada | Baja (3.5) | 1.1% | — | Forgerock Openam | 14/11/2014 | 17/6/2026 | The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service (infinite loop) via a crafted cookie in a request. | |
| Modificada | Media (6.8) | 1.1% | — | Projectforge | 2/1/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in ProjectForge before 5.3 allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) web/admin/, (2) web/core/, (3) web/dialog/, (4) web/fibu/, (5) web/mobile/, (6) web/task/, or (7) web/wicket/. | |
| Modificada | Baja (3.5) | 1.5% | — | Projectforge | 2/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the JsonBuilder implementation in ProjectForge before 5.3 allows remote authenticated users to inject arbitrary web script or HTML via an autocompletion string, related to web/core/JsonBuilder.java and web/wicket/autocompletion/PFAutoCompleteBehavior.java. | |
| Modificada | Baja (3.5) | 1.1% | — | Projectforge | 2/1/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ProjectForge before 3.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a validation message. |