Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.22% | — | Urbanandroid Twilight | 9/6/2023 | 17/6/2026 | An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files. | |
| Modificada | Alta (7.8) | 0.40% | — | Urbanandroid Twilight | 9/6/2023 | 17/6/2026 | An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files. | |
| Modificada | Media (5) | 3.9% | — | Twilightcms Twilight CMS | 9/9/2013 | 16/6/2026 | Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary files via a ..%5c (dot dot encoded backslash) in a GET request. | |
| Modificada | Media (4.3) | 1.2% | — | Twilightcms Twilight CMS | 9/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Twilight CMS 5.17 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the gallery/ page. | |
| Modificada | Media (4.3) | 3.0% | — | Twilightcms Twilight CMS | 4/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.8% | — | Twilight Utilities WEB Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to write arbitrary files via a .. (dot dot) in the attfile parameter. | |
| Modificada | Alta (7.5) | 3.8% | — | Twilight Utilities WEB Server | 31/12/2004 | 16/6/2026 | Buffer overflow in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request with a long attfile attribute. | |
| Modificada | Alta (7.8) | 3.2% | — | Twilight WebserverAI | 31/12/2003 | 16/6/2026 | Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376. |