Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
233 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Chainsafe Ethermint | 8/2/2021 | 17/6/2026 | Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction through the application. | |
| Modificada | Media (6.5) | 1.7% | — | Tendermint | 26/1/2021 | 17/6/2026 | Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - written in any programming language - and securely replicates it on many machines. Tendermint Core v0.34.0 introduced a new way of handling evidence of misbehavior. As part of this, we added a new… | |
| Modificada | Alta (7.1) | 2.7% | — | Mintegraladsdk | 19/10/2020 | 17/6/2026 | This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. Mintegral and their partners (advertisers) can remotely execute arbitrary code on a user device. | |
| Modificada | Media (4.7) | 0.86% | — | Mintegraladsdk | 15/10/2020 | 17/6/2026 | This affects all versions of package com.mintegral.msdk:alphab. The Android SDK distributed by the company contains malicious functionality in this module that tracks: 1. Downloads from Google urls either within Google apps or via browser including file downloads, e-mail attachments and Google Docs links. 2. All apk… | |
| Modificada | Alta (8.1) | 1.2% | — | Mintegraladsdk | 24/8/2020 | 17/6/2026 | This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attribution fraud. Mintegral can remotely activate hooks on the UIApplication, openURL,… | |
| Modificada | Media (6.5) | 0.91% | — | Tendermint | 2/7/2020 | 17/6/2026 | TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it run for some time and restart it (**without changing chainID**). A malicious block proposer (even with a minimal amount of stake) can use… | |
| Modificada | Baja (3.7) | 1.4% | — | Tendermint | 10/4/2020 | 17/6/2026 | Tendermint before versions 0.33.3, 0.32.10, and 0.31.12 has a denial-of-service vulnerability. Tendermint does not limit the number of P2P connection requests. For each p2p connection, it allocates XXX bytes. Even though this memory is garbage collected once the connection is terminated (due to duplicate IP or… | |
| Modificada | Alta (7.8) | 2.1% | 💥 PoC | Gnome GthumbLinuxmint PIXDebian Linux | 16/3/2020 | 17/6/2026 | A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file. | |
| Modificada | Alta (7.5) | 1.0% | — | Linuxmint | 7/2/2020 | 16/6/2026 | LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintUpdate. | |
| Modificada | Alta (7.5) | 0.88% | — | Linuxmint | 7/2/2020 | 16/6/2026 | LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintNanny. | |
| Modificada | Alta (7.8) | 8.2% | 💥 Exploit | Linuxmint Mintinstall | 2/10/2019 | 17/6/2026 | mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports. | |
| Modificada | Media (6.5) | 2.2% | — | MI BrowserMint Browser | 5/4/2019 | 17/6/2026 | A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of an https URL before the ?q= substring is not shown to the user. | |
| Modificada | Alta (7.5) | 1.1% | — | Cashbackmintable Project Cashbackmintable | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Sample Token (STK) (Contract Name: cashBackMintable), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (8.1) | 2.2% | — | Debian LinuxLinuxmint Cinnamon | 2/7/2018 | 17/6/2026 | An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location.… | |
| Modificada | Crítica (9.8) | 2.5% | — | Pepperminty-wiki Project Pepperminty-wiki | 3/1/2018 | 17/6/2026 | Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution | |
| Modificada | Media (6.7) | 0.33% | — | Compulab Intense PC FirmwareCompulab Mintbox 2 Firmware | 6/6/2017 | 17/6/2026 | CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by leveraging administrative privileges. | |
| Modificada | Alta (7.2) | 0.33% | — | Linuxmint Linux MintGnome GTKCanonical Ubuntu | 16/1/2015 | 17/6/2026 | GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Mintboard | 29/7/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Mintboard 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) pass parameter in views/login.php or (3) name or (4) pass parameter in views/signup.php. | |
| Modificada | Media (6.8) | 0.75% | — | Nijskens RAF Admintools | 17/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Admin tools module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors involving "not checking tokens." | |
| Modificada | Media (4.3) | 1.3% | — | Nijskens RAF Admintools | 17/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Admin tools module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Openmairie Opencominterne | 12/5/2010 | 16/6/2026 | Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069. | |
| Modificada | Alta (7.5) | 1.0% | — | Dirk Maiwert Datamints Newsticker | 15/3/2010 | 16/6/2026 | SQL injection vulnerability in the datamints Newsticker (datamints_newsticker) extension before 0.7.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Docmint | 15/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0 and 2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (8.1) | 3.4% | 💥 Exploit | Kmint21 Golden FTP Server | 3/12/2009 | 16/6/2026 | Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mint Haber Sistemi | 18/1/2007 | 16/6/2026 | SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter. |