Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.34% | — | Shipmondo Pakkelabels-for-woocommerceAI | 28/3/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Shipmondo Shipmondo – A complete shipping solution for WooCommerce pakkelabels-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Shipmondo – A complete shipping solution for WooCommerce: from n/a through <= 5.0.3. | |
| Aplazada | Media (6.5) | 0.36% | — | Odyno EndomondowpAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Odyno EndomondoWP endomondowp allows Stored XSS.This issue affects EndomondoWP: from n/a through <= 0.1.1. | |
| Modificada | Crítica (9.1) | 1.1% | — | Mandriva Mondo | 7/11/2019 | 16/6/2026 | Mondo 2.24 has insecure handling of temporary files. | |
| Modificada | Alta (7.5) | 1.3% | — | Infocus Mondopad | 9/10/2017 | 17/6/2026 | InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Manager to reach a file. | |
| Modificada | Media (5.5) | 0.86% | — | Infocuscorp Infocus Mondopad | 9/10/2017 | 17/6/2026 | Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document containing a link that has a UNC pathname associated with an attacker-controller server. In one specific scenario, the attacker provides an Excel spreadsheet, and the… | |
| Modificada | Alta (10) | 1.5% | — | Mondo Rescue | 2/4/2008 | 16/6/2026 | Unspecified vulnerability in Mondo Rescue before 2.2.5 has unknown impact and attack vectors, related to the use of (1) /tmp and (2) MINDI_CACHE. | |
| Modificada | Media (5) | 2.3% | — | Mondosoft Mondosearch | 2/4/2003 | 16/6/2026 | MsmMask.exe in MondoSearch 4.4 allows remote attackers to obtain the source code of scripts via the mask parameter. | |
| Modificada | Alta (7.5) | 3.4% | — | Matthew Mondor MmftpdMatthew Mondor Mmmail | 4/10/2002 | 16/6/2026 | Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier. |