Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1.3)1.5%—Qusetions Minicode-pythonAI22/7/202622/7/2026
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high complexity level is…
AplazadaAlta (8.5)0.19%—Ipknowledge Musetheque V4AIIpknowledge V4l1AI15/5/202617/6/2026
Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done.
AplazadaMedia (4.8)0.13%—Ipknowledge Musetheque V4AI15/5/202617/6/2026
Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the information of the file.
AplazadaMedia (6.9)0.49%—MousetooltiptranslatorAI3/3/202517/6/2026
The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vulnerable to SSRF attacks. The pdf.mjs script uses the URL parameter from the current URL as the file to download and display to the extension user. Because pdf.mjs is…
AplazadaMedia (4.7)0.46%—CGI UsetAI12/12/202417/6/2026
Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "File Name" page (/cgi/uset.cgi?-cfilename) in the User Settings menu improperly filters the "file name" and wildcard character input field. By exploiting the wildcard…
ModificadaMedia (4.3)1.6%—FusetalkFusetalk. Fusetalk4/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter.
ModificadaAlta (7.5)1.1%—Fusetalk11/7/200716/6/2026
SQL injection vulnerability in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via the FTVAR_SUBCAT (txForumID) parameter to forum/index.cfm and possibly other unspecified components, related to forum/include/error/forumerror.cfm.
ModificadaMedia (4.3)4.1%—Fusetalk21/6/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3)…
ModificadaAlta (7.5)1.0%—Fusetalk20/6/200716/6/2026
SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch may have been released privately between April and June 2007. NOTE: this issue may overlap CVE-2007-3273.
ModificadaAlta (7.5)1.1%—Fusetalk19/6/200716/6/2026
SQL injection vulnerability in index.cfm in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.5)1.8%—Fusetalk31/12/200416/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.
ModificadaMedia (4.3)1.3%—E-zone Media Inc. Fusetalk13/10/200416/6/2026
Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag.
ModificadaMedia (5)1.6%—E-zone Media Inc. Fusetalk5/5/200416/6/2026
FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.
ModificadaMedia (4.3)0.94%—E-zone Media Inc. Fusetalk31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script.
ModificadaAlta (7.2)0.44%—University OF Massachusetts Scheme20/10/200016/6/2026
umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files.