Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Booksellerscanada Free Canadian Author Previews | 21/10/2014 | 17/6/2026 | The Free Canadian Author Previews (aka com.booksellerscanada.authorpreview) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 1.1% | — | Lesterchan Wp-postviews | 10/4/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. | |
| Modificada | Baja (2.1) | 2.0% | — | Views Project Views | 27/3/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Views module 7.x-3.x before 7.x-3.6 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via certain view configuration fields. | |
| Modificada | Media (4.3) | 1.2% | — | Ubercart Views Project UC Views | 27/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field. | |
| Modificada | Media (4.3) | 5.3% | 💥 Exploit | Terillion Reviews Plugin | 22/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field. | |
| Modificada | Media (4.9) | 1.1% | — | Karim Ratib Views Bulk Operations | 7/10/2012 | 16/6/2026 | Unspecified vulnerability in the Views Bulk Operations module 6 before 6.x-1.10 for Drupal allows remote authenticated users with user management permissions to bypass intended access restrictions and delete anonymous users (user 0) via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Mark Theunissen Views Lang Switch | 5/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in theme/views_lang_switch.theme.inc in the Views Language Switcher module before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 1.6% | — | Ubercart Views Project UC Views | 14/8/2012 | 16/6/2026 | Unspecified vulnerability in certain default views in the Ubercart Views module 6.x before 6.x-3.2 for Drupal allows remote attackers to obtain sensitive information via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Ilog Jviews GanttIBM Tivoli Change AND Configuration Management Database | 2/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | Earl Miles Views | 17/2/2012 | 16/6/2026 | SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments." | |
| Modificada | Media (4.3) | 1.9% | — | Earl Miles Views | 23/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path. | |
| Modificada | Media (4.3) | 1.0% | — | Earl Miles Views | 23/12/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title. | |
| Modificada | Media (6.8) | 0.61% | — | Earl Miles Views | 23/12/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views. | |
| Modificada | Alta (7.5) | 2.2% | — | Karim Ratib Views Bulk Operations | 27/6/2009 | 16/6/2026 | Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote attackers to bypass intended access restrictions and modify "nodes or classes of nodes" via unknown vectors, probably related to registered procedures (aka actions). | |
| Modificada | Media (4) | 0.99% | — | Angrydonuts Views | 16/6/2009 | 16/6/2026 | Drupal 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to bypass access restrictions and (1) read unpublished content from anonymous users when a view is already configured to display the content, and (2) read private content in generated queries. | |
| Modificada | Baja (3.5) | 0.90% | — | Drupal Views | 16/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via (1) exposed filters in the Views UI administrative interface and in the (2) view name parameter in the define custom views feature. NOTE: vector 2 is… | |
| Modificada | Media (4.3) | 1.1% | — | Drupal Views Bulk Operations | 13/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to… | |
| Modificada | Alta (7.5) | 1.3% | — | Drupal Views | 2/2/2009 | 16/6/2026 | SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "an exposed filter on CCK text fields." | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Zeescripts Zeereviews | 13/8/2008 | 16/6/2026 | SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | |
| Modificada | Media (6.4) | 2.3% | 💥 Exploit | Prozilla Reviews | 15/4/2008 | 16/6/2026 | Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Lykoszine Lykos Reviews Module | 2/4/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attackers to execute arbitrary SQL commands via the uid parameter in a u action. | |
| Modificada | Alta (10) | 1.8% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorized activities. | |
| Modificada | Media (5) | 1.6% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via long or malformed ICMP packets. | |
| Modificada | Media (5) | 1.6% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via multiple connections to the server. | |
| Modificada | Alta (7.5) | 1.6% | — | Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+4 | 7/1/2003 | 16/6/2026 | The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requests. |