Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

226 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.27%—Booksellerscanada Free Canadian Author Previews21/10/201417/6/2026
The Free Canadian Author Previews (aka com.booksellerscanada.authorpreview) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.8)1.1%—Lesterchan Wp-postviews10/4/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
ModificadaBaja (2.1)2.0%—Views Project Views27/3/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 7.x-3.x before 7.x-3.6 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via certain view configuration fields.
ModificadaMedia (4.3)1.2%—Ubercart Views Project UC Views27/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.
ModificadaMedia (4.3)5.3%💥 ExploitTerillion Reviews Plugin22/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field.
ModificadaMedia (4.9)1.1%—Karim Ratib Views Bulk Operations7/10/201216/6/2026
Unspecified vulnerability in the Views Bulk Operations module 6 before 6.x-1.10 for Drupal allows remote authenticated users with user management permissions to bypass intended access restrictions and delete anonymous users (user 0) via unspecified vectors.
ModificadaMedia (4.3)2.0%—Mark Theunissen Views Lang Switch5/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in theme/views_lang_switch.theme.inc in the Views Language Switcher module before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (5)1.6%—Ubercart Views Project UC Views14/8/201216/6/2026
Unspecified vulnerability in certain default views in the Ubercart Views module 6.x before 6.x-3.2 for Drupal allows remote attackers to obtain sensitive information via unknown attack vectors.
ModificadaMedia (4.3)1.1%—IBM Ilog Jviews GanttIBM Tivoli Change AND Configuration Management Database2/3/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.6%—Earl Miles Views17/2/201216/6/2026
SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."
ModificadaMedia (4.3)1.9%—Earl Miles Views23/12/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.
ModificadaMedia (4.3)1.0%—Earl Miles Views23/12/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.
ModificadaMedia (6.8)0.61%—Earl Miles Views23/12/201016/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.
ModificadaAlta (7.5)2.2%—Karim Ratib Views Bulk Operations27/6/200916/6/2026
Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote attackers to bypass intended access restrictions and modify "nodes or classes of nodes" via unknown vectors, probably related to registered procedures (aka actions).
ModificadaMedia (4)0.99%—Angrydonuts Views16/6/200916/6/2026
Drupal 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to bypass access restrictions and (1) read unpublished content from anonymous users when a view is already configured to display the content, and (2) read private content in generated queries.
ModificadaBaja (3.5)0.90%—Drupal Views16/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via (1) exposed filters in the Views UI administrative interface and in the (2) view name parameter in the define custom views feature. NOTE: vector 2 is…
ModificadaMedia (4.3)1.1%—Drupal Views Bulk Operations13/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to…
ModificadaAlta (7.5)1.3%—Drupal Views2/2/200916/6/2026
SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "an exposed filter on CCK text fields."
ModificadaAlta (7.5)1.2%💥 ExploitZeescripts Zeereviews13/8/200816/6/2026
SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
ModificadaMedia (6.4)2.3%💥 ExploitProzilla Reviews15/4/200816/6/2026
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php.
ModificadaAlta (7.5)2.2%💥 ExploitLykoszine Lykos Reviews Module2/4/200716/6/2026
SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attackers to execute arbitrary SQL commands via the uid parameter in a u action.
ModificadaAlta (10)1.8%—Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+47/1/200316/6/2026
Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorized activities.
ModificadaMedia (5)1.6%—Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+47/1/200316/6/2026
The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via long or malformed ICMP packets.
ModificadaMedia (5)1.6%—Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+47/1/200316/6/2026
The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via multiple connections to the server.
ModificadaAlta (7.5)1.6%—Polycom Viewstation 128Polycom Viewstation 512Polycom Viewstation DCPPolycom Viewstation FX Vs4000+47/1/200316/6/2026
The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requests.
Orbitaley — Vulnerabilidades