Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.29% | — | Openwrt LedeAI | 27/1/2026 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7603e/src/mt7603_wifi/common modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1. | |
| Aplazada | Crítica (9.2) | 0.30% | — | Openwrt LedeAI | 27/1/2026 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7615d/src/mt_wifi/embedded/security modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1. | |
| Analizada | Crítica (9.8) | 0.53% | — | Unhandledexpression Trailer | 9/5/2025 | 17/6/2026 | lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero. | |
| Aplazada | Media (6.5) | 0.34% | — | Olaf Lederer Eo4wpAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP fw-integration-for-emailoctopus allows Stored XSS.This issue affects EO4WP: from n/a through <= 1.0.8.4. | |
| Aplazada | Media (6.5) | 0.23% | — | Olaf Lederer Fws-ajax-contact-formAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer Ajax Contact Form fws-ajax-contact-form allows Stored XSS.This issue affects Ajax Contact Form: from n/a through <= 1.4.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Olaf Lederer Eo4wpAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP fw-integration-for-emailoctopus allows Stored XSS.This issue affects EO4WP: from n/a through <= 1.0.8.1. | |
| Aplazada | Media (6.5) | 0.23% | — | LedenbeheerAI | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ledenbeheer Ledenbeheer ledenbeheer-external-connection allows Stored XSS.This issue affects Ledenbeheer: from n/a through <= 2.1.0. | |
| Modificada | Media (5.5) | 0.23% | — | Simpledesign Diary With Lock\ | 24/5/2023 | 17/6/2026 | A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the… | |
| Modificada | Crítica (9.8) | 0.72% | — | Libimobiledevice Libplist | 21/2/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The patch is named c086cb139af7c82845f6d565e636073ff4b37440. It is recommended to… | |
| Modificada | Alta (7.8) | 0.20% | — | Elecom Camera AssistantElecom Quickfiledealer | 15/2/2023 | 17/6/2026 | Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (6.1) | 2.7% | — | Mobiledetect | 4/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. This issue affects the function initLayoutType of the file examples/session_example.php of the component Example. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated… | |
| Modificada | Alta (8.1) | 1.6% | — | Openwrt LedeOpenwrt | 16/3/2020 | 17/6/2026 | An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads… | |
| Modificada | Media (6.1) | 1.1% | — | Vegadesign Profiledesign CMS | 13/5/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid, (6) cat, or (7) orderby parameter. | |
| Modificada | Media (6.1) | 0.66% | — | Openwrt LedeOpenwrt | 28/11/2018 | 17/6/2026 | cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI. | |
| Modificada | Media (5.5) | 1.5% | — | Libimobiledevice Libplist | 20/4/2017 | 17/6/2026 | Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file. | |
| Modificada | Alta (7.5) | 2.7% | — | Libimobiledevice Libplist | 3/3/2017 | 17/6/2026 | The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free. | |
| Modificada | Alta (7.5) | 2.9% | — | Libimobiledevice Libplist | 3/3/2017 | 17/6/2026 | libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero. | |
| Modificada | Media (5.5) | 1.3% | — | Libimobiledevice Libplist | 3/3/2017 | 17/6/2026 | The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file. | |
| Modificada | Crítica (9.1) | 3.8% | — | Libimobiledevice Libplist | 21/1/2017 | 17/6/2026 | The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short. | |
| Modificada | Crítica (9.1) | 2.9% | — | Libimobiledevice Libplist | 11/1/2017 | 17/6/2026 | The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data. | |
| Modificada | Media (5.3) | 3.0% | — | LibimobiledeviceLibimobiledevice LibusbmuxdCanonical Ubuntu LinuxOpensuse Leap+1 | 13/6/2016 | 17/6/2026 | The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket. | |
| Modificada | Media (5.4) | 0.27% | — | Mobiledeluxe BIG WIN Slots - Slot Machines | 9/9/2014 | 17/6/2026 | The Big Win Slots - Slot Machines (aka com.gosub60.BigWinSlots) application 1.11.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mobiledeluxe Solitaire Deluxe | 9/9/2014 | 17/6/2026 | The Solitaire Deluxe (aka com.gosub60.solfree2) application 2.8.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (3.3) | 0.27% | — | Libimobiledevice | 19/1/2014 | 16/6/2026 | userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/. | |
| Modificada | Media (5.1) | 1.5% | — | Blaine Lang Filedepot | 27/6/2012 | 16/6/2026 | The filedepot module 6.x-1.x before 6.x-1.3 for Drupal, when accessed using multiple different browsers from the same IP address, causes Internet Explorer sessions to "switch users" when uploading a file, which has unspecified impact possibly involving file uploads to the wrong user directory, aka "Session Management… |