Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.29%—Openwrt LedeAI27/1/202617/6/2026
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7603e/src/mt7603_wifi/common modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1.
AplazadaCrítica (9.2)0.30%—Openwrt LedeAI27/1/202617/6/2026
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7615d/src/mt_wifi/embedded/security modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1.
AnalizadaCrítica (9.8)0.53%—Unhandledexpression Trailer9/5/202517/6/2026
lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero.
AplazadaMedia (6.5)0.34%—Olaf Lederer Eo4wpAI27/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP fw-integration-for-emailoctopus allows Stored XSS.This issue affects EO4WP: from n/a through <= 1.0.8.4.
AplazadaMedia (6.5)0.23%—Olaf Lederer Fws-ajax-contact-formAI15/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer Ajax Contact Form fws-ajax-contact-form allows Stored XSS.This issue affects Ajax Contact Form: from n/a through <= 1.4.1.
AplazadaMedia (6.5)0.21%—Olaf Lederer Eo4wpAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP fw-integration-for-emailoctopus allows Stored XSS.This issue affects EO4WP: from n/a through <= 1.0.8.1.
AplazadaMedia (6.5)0.23%—LedenbeheerAI31/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ledenbeheer Ledenbeheer ledenbeheer-external-connection allows Stored XSS.This issue affects Ledenbeheer: from n/a through <= 2.1.0.
ModificadaMedia (5.5)0.23%—Simpledesign Diary With Lock\24/5/202317/6/2026
A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the…
ModificadaCrítica (9.8)0.72%—Libimobiledevice Libplist21/2/202317/6/2026
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The patch is named c086cb139af7c82845f6d565e636073ff4b37440. It is recommended to…
ModificadaAlta (7.8)0.20%—Elecom Camera AssistantElecom Quickfiledealer15/2/202317/6/2026
Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (6.1)2.7%—Mobiledetect4/2/202317/6/2026
A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. This issue affects the function initLayoutType of the file examples/session_example.php of the component Example. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated…
ModificadaAlta (8.1)1.6%—Openwrt LedeOpenwrt16/3/202017/6/2026
An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads…
ModificadaMedia (6.1)1.1%—Vegadesign Profiledesign CMS13/5/201917/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid, (6) cat, or (7) orderby parameter.
ModificadaMedia (6.1)0.66%—Openwrt LedeOpenwrt28/11/201817/6/2026
cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.
ModificadaMedia (5.5)1.5%—Libimobiledevice Libplist20/4/201717/6/2026
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.
ModificadaAlta (7.5)2.7%—Libimobiledevice Libplist3/3/201717/6/2026
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free.
ModificadaAlta (7.5)2.9%—Libimobiledevice Libplist3/3/201717/6/2026
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
ModificadaMedia (5.5)1.3%—Libimobiledevice Libplist3/3/201717/6/2026
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
ModificadaCrítica (9.1)3.8%—Libimobiledevice Libplist21/1/201717/6/2026
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.
ModificadaCrítica (9.1)2.9%—Libimobiledevice Libplist11/1/201717/6/2026
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data.
ModificadaMedia (5.3)3.0%—LibimobiledeviceLibimobiledevice LibusbmuxdCanonical Ubuntu LinuxOpensuse Leap+113/6/201617/6/2026
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
ModificadaMedia (5.4)0.27%—Mobiledeluxe BIG WIN Slots - Slot Machines9/9/201417/6/2026
The Big Win Slots - Slot Machines (aka com.gosub60.BigWinSlots) application 1.11.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Mobiledeluxe Solitaire Deluxe9/9/201417/6/2026
The Solitaire Deluxe (aka com.gosub60.solfree2) application 2.8.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaBaja (3.3)0.27%—Libimobiledevice19/1/201416/6/2026
userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.
ModificadaMedia (5.1)1.5%—Blaine Lang Filedepot27/6/201216/6/2026
The filedepot module 6.x-1.x before 6.x-1.3 for Drupal, when accessed using multiple different browsers from the same IP address, causes Internet Explorer sessions to "switch users" when uploading a file, which has unspecified impact possibly involving file uploads to the wrong user directory, aka "Session Management…