Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | Apple NumbersApple IworkApple PagesApple Keynote | 18/10/2015 | 17/6/2026 | The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document. | |
| Modificada | Media (4.3) | 1.4% | — | 4homepages 4images | 5/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php. | |
| Modificada | Media (6.8) | 0.58% | — | IBM Openpages GRC Platform | 3/10/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Baja (3.5) | 0.78% | — | IBM Openpages GRC Platform | 3/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8916. | |
| Modificada | Media (4) | 0.97% | — | IBM Openpages GRC Platform | 3/10/2015 | 17/6/2026 | IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to obtain sensitive information by reading error messages. | |
| Modificada | Media (4) | 1.0% | — | IBM Openpages GRC Platform | 3/10/2015 | 17/6/2026 | IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to cause a denial of service (maintenance-mode transition and data-storage outage) by calling the System Administration Mode function. | |
| Modificada | Media (4) | 1.1% | — | IBM Openpages GRC Platform | 3/10/2015 | 17/6/2026 | IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to modify arbitrary user filters via a JSON request. | |
| Modificada | Baja (3.5) | 0.78% | — | IBM Openpages GRC Platform | 3/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0144. | |
| Modificada | Media (5) | 2.5% | — | Apple MAC OS XApple Iphone OSApple NumbersApple Keynote+2 | 16/8/2015 | 17/6/2026 | Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Baja (3.5) | 3.9% | 💥 Exploit | Landing Pages Project Landing Pages | 27/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php. | |
| Modificada | Media (6.5) | 3.8% | 💥 Exploit | Landing Pages Project Landing Pages | 27/5/2015 | 17/6/2026 | SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php. | |
| Modificada | Media (4.3) | 2.0% | — | Instasqueeze Sexy Squeeze Pages | 2/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to lp/index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Protected Pages Project Protected Pages | 20/11/2014 | 17/6/2026 | The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path. | |
| Modificada | Media (5.4) | 0.27% | — | Avantar White & Yellow Pages | 10/9/2014 | 17/6/2026 | The White & Yellow Pages (aka com.avantar.wny) application 5.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.30% | — | Yellowbook Yellow Pages Local Search | 9/9/2014 | 17/6/2026 | The Yellow Pages Local Search (aka com.yellowbook.android2) application 11.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.0% | — | IBM Openpages GRC Platform | 27/6/2014 | 17/6/2026 | IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors. | |
| Modificada | Media (6.4) | 1.2% | — | IBM Openpages GRC Platform | 27/6/2014 | 16/6/2026 | Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown vectors. | |
| Modificada | Media (4.3) | 0.97% | — | Gordon Heydon Secure Pages | 9/6/2014 | 16/6/2026 | The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used instead of HTTPS and makes it easier for remote attackers to obtain sensitive information via a crafted web page. | |
| Modificada | Alta (7.5) | 4.2% | — | Apple PagesApple MAC OS XApple Iphone OS | 24/1/2014 | 17/6/2026 | Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file. | |
| Modificada | Media (4.3) | 1.2% | — | Modpagespeed MOD Pagespeed | 2/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.x, 1.0.22.7, 1.1.x, 1.24.1, 1.3.25.1 through 1.3.25.4, 1.4.26.1 through 1.4.26.4, 1.5.27.1 through 1.5.27.3, and 1.6.29.1 through 1.6.29.6 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified… | |
| Modificada | Alta (7.5) | 2.5% | — | Landing Pages Project Landing Pages Plugin | 23/10/2013 | 17/6/2026 | SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php. | |
| Modificada | Alta (7.5) | 3.9% | — | Impresspages CMS | 6/10/2012 | 16/6/2026 | Eval injection vulnerability in ip_cms/modules/standard/content_management/actions.php in ImpressPages CMS 1.0.12 and possibly other versons before 1.0.13 allows remote attackers to execute arbitrary code via the cm_group parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Google MOD Pagespeed | 15/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 0.68% | — | Google MOD Pagespeed | 15/9/2012 | 16/6/2026 | The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers. | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | 4homepages 4images | 8/2/2012 | 16/6/2026 | Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter. |