Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Fylet Secure Large File Sender | 19/10/2014 | 17/6/2026 | The Fylet Secure Large File Sender (aka com.application.fyletFileSender) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.30% | — | Kicksend Photo Prints | 9/9/2014 | 17/6/2026 | The Kicksend Photo Prints (aka com.kicksend.android.print) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.30% | — | Kicksend\ | 9/9/2014 | 17/6/2026 | The Kicksend: Share & Print Photos (aka com.kicksend.android) application 3.3.2.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (1.9) | 0.64% | — | FreebsdHpuxFedoraproject FedoraSendmail | 4/6/2014 | 17/6/2026 | The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program. | |
| Modificada | Media (5) | 3.9% | — | HP Color Laserjet 3000HP Color Laserjet 3800HP Color Laserjet 4700HP Color Laserjet 4730 MFP+33 | 29/4/2013 | 16/6/2026 | Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and CP6015; Color LaserJet Enterprise CP4xxx; and 9250c Digital Sender… | |
| Modificada | Alta (10) | 14% | — | HP Color Laserjet 3000HP Color Laserjet 3800HP Color Laserjet 4700HP Color Laserjet 4730+37 | 1/12/2011 | 16/6/2026 | The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware… | |
| Modificada | Baja (1.2) | 0.43% | — | HP Multifunction Peripheral Digital Sending Software | 23/10/2011 | 16/6/2026 | HP MFP Digital Sending Software 4.9x through 4.91.21 allows local users to obtain sensitive workflow-metadata information via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.58% | — | HP Multifunction Peripheral Digital Sending Software | 7/3/2011 | 16/6/2026 | HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to require authentication. | |
| Modificada | Media (4.7) | 0.47% | — | HP Multifunction Peripheral Digital Sending Software | 14/5/2010 | 16/6/2026 | Unspecified vulnerability in HP Multifunction Peripheral (MFP) Digital Sending Software before 4.18.3 allows local users to bypass intended restrictions on the MFP "Send to e-mail" feature, and obtain sensitive information, via unknown vectors. | |
| Modificada | Alta (7.5) | 2.4% | — | Sendmail | 4/1/2010 | 16/6/2026 | sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers… | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | Alstrasoft Sendit | 11/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in send/files/. | |
| Modificada | Alta (7.5) | 1.6% | — | Adbnewssender | 13/7/2009 | 16/6/2026 | Directory traversal vulnerability in maillinglist/admin/change_config.php in ADbNewsSender before 1.5.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Adbnewssender | 13/7/2009 | 16/6/2026 | Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter to setup/index.php. | |
| Modificada | Media (5) | 13% | 💥 Exploit | Sendmail | 5/5/2009 | 16/6/2026 | Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header. | |
| Modificada | Alta (7.6) | 3.0% | — | HP 8100c Digital SenderHP 9100c Digital SenderHP 9200c Digital SenderHP 9250c Digital Sender+150 | 18/3/2009 | 16/6/2026 | The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access. | |
| Modificada | Media (5.1) | 1.1% | — | HP 8100c Digital SenderHP 9100c Digital SenderHP 9200c Digital SenderHP 9250c Digital Sender+150 | 18/3/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network… | |
| Modificada | Alta (7.8) | 7.4% | — | HP 9200c Digital SenderHP Color Laserjet 4370mfpHP Color Laserjet 9500mfpHP Laserjet 2410+9 | 5/2/2009 | 16/6/2026 | Directory traversal vulnerability in the HP JetDirect web administration interface in the HP-ChaiSOE 1.0 embedded web server on the LaserJet 9040mfp, LaserJet 9050mfp, and Color LaserJet 9500mfp before firmware 08.110.9; LaserJet 4345mfp and 9200C Digital Sender before firmware 09.120.9; Color LaserJet 4730mfp before… | |
| Modificada | Media (4.3) | 1.0% | — | Adbnewssender | 4/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ADbNewsSender before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) subscribing and (2) unsubscribing. | |
| Modificada | Alta (7.5) | 1.0% | — | Adbnewssender Project Adbnewssender | 4/2/2009 | 16/6/2026 | SQL injection vulnerability in ADbNewsSender before 1.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in (1) opt_in_out.php.inc, (2) confirmation.php.inc, and (3) renewal.php.inc in mailinglist/. | |
| Modificada | Media (6.9) | 0.38% | — | Freebsd-sendpr | 18/11/2008 | 16/6/2026 | sendbug in freebsd-sendpr 3.113+5.3 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pr.##### temporary file. | |
| Modificada | Media (4.3) | 1.1% | — | Typo3 Send A Card | 7/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Send-A-Card (sr_sendcard) extension 2.2.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Beehive Software Sendfile.net | 4/3/2008 | 16/6/2026 | The outboxWriteUnsent function in FTPThread.class in SendFile.jar for Beehive Software SendFile.NET uses hard-coded credentials for an FTP server, which allows remote attackers to gain privileges. | |
| Modificada | Media (6.8) | 1.3% | — | Jacob Hinkle Godsend | 4/10/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Jacob Hinkle GodSend 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the SCRIPT_DIR parameter to (1) gtk/main.inc.php or (2) cmdline.inc.php. NOTE: vector 2 is disputed by CVE because it is contained in unaccessible code, requiring that two… | |
| Modificada | Alta (7.8) | 2.9% | 💥 Exploit | Sendcard | 6/6/2007 | 16/6/2026 | Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sc_language parameter. | |
| Modificada | Media (5) | 1.2% | — | Sendcard | 6/6/2007 | 16/6/2026 | SendCard 3.3.0 allows remote attackers to obtain sensitive information via an invalid sc_language parameter to sendcard.php, which reveals the path in an error message. |