Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.1% | — | Coastercms | 21/12/2020 | 9/7/2026 | Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/application. | |
| Modificada | Media (5.3) | 1.1% | — | Cobham SEA TEL Coastal 18 FirmwareCobham Sailor 600 Vsat KU FirmwareCobham Sailor 800 Vsat FirmwareCobham Sailor 900 Vsat Firmware+7 | 15/9/2019 | 17/6/2026 | Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latitude and longitude, via the public SNMP community. | |
| Modificada | Media (6.1) | 1.00% | — | Web-feet Coaster CMS | 4/10/2018 | 17/6/2026 | A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product. | |
| Modificada | Media (5.9) | 0.85% | — | Sccu Space Coast Credit Union | 5/5/2017 | 17/6/2026 | The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.29% | — | Appa-apps TOP Roller Coasters Europe 2 | 21/10/2014 | 17/6/2026 | The Top Roller Coasters Europe 2 (aka com.appaapps.top10tallesteuropeanrollercoasters2) application @7F050001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.29% | — | Appa-apps TOP Roller Coasters Europe 1 | 19/10/2014 | 17/6/2026 | The Top Roller Coasters Europe 1 (aka com.appaapps.top10tallesteuropeanrollercoasters1) application @7F050001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Gcefcu Gulf Coast Educators FCU | 19/10/2014 | 17/6/2026 | The Gulf Coast Educators FCU (aka com.metova.cuae.gcefcu) application 1.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (8.5) | 2.3% | — | Coastal Coast | 24/10/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute arbitrary PHP code via a URL in the sections_file parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Coastal Data Management E-quick Cart | 22/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in e-Quick Cart allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in shopaddtocart.asp, (2) strpemail parameter in shopprojectlogin.asp, and (3) id parameter in shoptellafriend.asp. | |
| Modificada | Media (4.3) | 1.3% | — | Coastal Data Management E-quick Cart | 22/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in e-Quick Cart allow remote attackers to inject arbitrary web script or HTML via the (1) strgifttoname parameter in shopgift.asp, (2) strfirstname parameter in shopmaillist.asp, (3) strpid parameter in shopprojectlogin.asp, and (4) Custname parameter in… | |
| Modificada | Alta (7.2) | 0.35% | — | Coast Satan | 26/6/1998 | 16/6/2026 | rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file. |