Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.60% | — | Spoonthemes Adifier SystemAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spoonthemes Adifier System allows PHP Local File Inclusion.This issue affects Adifier System: from n/a before 3.1.4. | |
| Modificada | Media (5.5) | 0.16% | — | Spooncast Spoon | 24/1/2024 | 17/6/2026 | Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service. | |
| Modificada | Crítica (9.8) | 0.59% | — | Spoonthemes Adifier | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoon themes Adifier - Classified Ads WordPress Theme.This issue affects Adifier - Classified Ads WordPress Theme: from n/a before 3.1.4. | |
| Modificada | Crítica (9.8) | 0.76% | — | Spoonthemes Couponis | 19/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from n/a before 2.2. | |
| Modificada | Media (6.1) | 0.40% | — | Spoonthemes Adifier | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spoonthemes Adifier - Classified Ads WordPress Theme allows Reflected XSS.This issue affects Adifier - Classified Ads WordPress Theme: from n/a before 3.1.4. | |
| Modificada | Crítica (9.8) | 2.5% | — | Spoon-library Spoon LibraryFork-cms Fork CMS | 26/8/2019 | 17/6/2026 | Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object. | |
| Modificada | Alta (7.5) | 2.8% | — | Ingy Spoon | 4/6/2014 | 16/6/2026 | Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Spoonlabs Vivvo Article Management CMS | 21/7/2007 | 16/6/2026 | SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Spoonlabs Vivvo Article Management CMS | 21/2/2007 | 16/6/2026 | Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the root parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Spoonlabs Vivvo Article Management CMS | 30/1/2007 | 16/6/2026 | SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715. NOTE: The provenance of this information is unknown; the details are… | |
| Modificada | Media (5.1) | 3.4% | 💥 Exploit | Spoonlabs Vivvo Article Management CMS | 12/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the classified_path parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Spoonlabs Vivvo Article Management CMS | 12/9/2006 | 16/6/2026 | SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | Pi-soft Spoonftp | 25/3/2002 | 16/6/2026 | Pi-Soft SpoonFTP 1.1 and earlier allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command. | |
| Modificada | Alta (7.5) | 2.0% | — | Pi-soft Spoonftp | 20/9/2001 | 16/6/2026 | Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD) command. | |
| Modificada | Alta (7.5) | 2.5% | — | Pi-soft Spoonftp | 30/5/2001 | 16/6/2026 | Buffer overflow in SpoonFTP 1.0.0.12 allows remote attackers to execute arbitrary code via a long argument to the commands (1) CWD or (2) LIST. |