Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | 0.18% | — | NET Whois RAWAI | 5/10/2026 | 5/10/2026 | Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and… | |
| Aplazada | Alta (8.6) | 0.16% | — | ARM WhoisAI | 1/6/2026 | 22/7/2026 | Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler… | |
| Aplazada | Crítica (9.3) | 0.92% | — | ARM WhoisAI | 1/6/2026 | 22/7/2026 | Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 bytes with shellcode to overwrite the structured exception handler and gain… | |
| Aplazada | Media (6.9) | 0.14% | — | ARM WhoisAI | 30/5/2026 | 22/7/2026 | Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 bytes into the IP address or domain input field to trigger a denial of service condition. | |
| Aplazada | Media (5.1) | 0.24% | — | Powie Whois Domain CheckAI | 13/5/2026 | 17/6/2026 | Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in the pwhois_settings.php… | |
| Modificada | Crítica (9.8) | 0.97% | — | Furqansofware Node Whois | 19/12/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible to launch the attack remotely. The name of the patch… | |
| Modificada | Media (6.1) | 0.63% | — | Phpwhois Project Phpwhois | 29/11/2021 | 17/6/2026 | phpWhois (last update Jun 30 2021) is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET['query'] then there is a XSS vulnerability. | |
| Modificada | Media (6.1) | 0.97% | — | Netattingo Wp-whois-domain | 13/9/2019 | 17/6/2026 | The wp-whois-domain plugin 1.0.0 for WordPress has XSS via the pages/func-whois.php domain parameter. | |
| Modificada | Crítica (9.8) | 6.2% | — | Phpwhois Project Phpwhois | 20/8/2018 | 17/6/2026 | phpWhois allows remote attackers to execute arbitrary code via a crafted whois record. | |
| Modificada | Media (6.1) | 1.1% | — | Clickfraud-monitoring Adsense-click-fraud-monitoringPhpwhois Project Phpwhois | 17/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary web script or HTML via the query parameter to whois.php. | |
| Modificada | Media (5.4) | 0.27% | — | Whoisit Who-is-it? Lite Name Caller Time Limited Free | 16/10/2014 | 17/6/2026 | The Who-is-it? Lite name caller time limited free (aka de.profiler.android.whoisit) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.2% | — | Phpace Samswhois | 23/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than CVE-2011-5193. | |
| Modificada | Baja (2.6) | 4.1% | — | Phpace Samswhois | 23/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194. | |
| Modificada | Alta (7.2) | 0.39% | — | Pwhois Layer Four Traceroute | 10/4/2011 | 16/6/2026 | Unspecified vulnerability in lft in pWhois Layer Four Traceroute (LFT) 3.x before 3.3 allows local users to gain privileges via a crafted command line. | |
| Modificada | Media (4.3) | 1.0% | — | Youjoomla YJ Whois | 8/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla! allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Matts Whois | 27/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mwhois.php in Matt Wilson Matt's Whois (MWhois) allows remote attackers to inject arbitrary web script or HTML via the domain parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Particle Soft Particle Whois | 12/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box." | |
| Modificada | Alta (7.5) | 2.8% | — | Whois | 20/10/2003 | 16/6/2026 | Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option. | |
| Modificada | Alta (10) | 4.7% | — | Rlaj Whois | 31/12/2002 | 16/6/2026 | Rlaj whois CGI script (whois.cgi) 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain name field. | |
| Modificada | Alta (7.5) | 7.0% | — | Network Solutions Rwhoisd | 6/12/2001 | 16/6/2026 | Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command. | |
| Modificada | Alta (7.5) | 2.9% | — | Network Solutions Rwhoisd | 22/11/2001 | 16/6/2026 | Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog, allows remote attackers to corrupt memory and possibly execute arbitrary code via a rwhois request that contains format specifiers. | |
| Modificada | Alta (10) | 13% | — | Kootenay WEB INC Whois | 19/12/2000 | 23/9/2026 | Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter. | |
| Modificada | Alta (7.5) | 2.7% | — | Internic Whois Lookup | 9/11/1999 | 16/6/2026 | Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | |
| Modificada | Alta (7.5) | 2.7% | — | Matts Whois | 9/11/1999 | 16/6/2026 | Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | |
| Modificada | Alta (7.5) | 8.9% | — | CC Whois | 9/11/1999 | 16/6/2026 | CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. |