Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.59%—NO Future Posts Project NO Future Posts30/5/202217/6/2026
The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
ModificadaMedia (6.1)0.94%—Futurepress Epub.js17/1/202217/6/2026
managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS.
ModificadaMedia (6.1)0.67%—HP Futuresmart 3HP Futuresmart 49/11/202117/6/2026
A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.
ModificadaAlta (7.8)0.29%—HP Futuresmart 49/11/202117/6/2026
A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution.
ModificadaCrítica (9.8)12%—HP Futuresmart 3HP Futuresmart 4HP Futuresmart 53/11/202117/6/2026
Certain HP Enterprise LaserJet, HP LaserJet Managed, HP Enterprise PageWide, HP PageWide Managed products may be vulnerable to potential buffer overflow.
ModificadaMedia (4.6)2.4%—HP Futuresmart 3HP Futuresmart 4HP Futuresmart 53/11/202117/6/2026
Certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed printers may be vulnerable to potential information disclosure.
ModificadaMedia (4.3)0.47%—Tipsandtricks-hq FAR Future Expiry Header1/11/202117/6/2026
The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
ModificadaMedia (5.4)0.47%—HP Futuresmart 4HP Futuresmart 529/10/202117/6/2026
Certain HP Enterprise LaserJet and PageWide MFPs may be vulnerable to stored cross site scripting (XSS).
ModificadaAlta (8.1)0.77%—Tiny Future Project Tiny Future8/8/202117/6/2026
An issue was discovered in the tiny_future crate before 0.4.0 for Rust. Future<T> does not have bounds on its Send and Sync traits.
ModificadaMedia (5.5)0.38%—Futures-intrusive Project Futures-intrusive31/12/202017/6/2026
An issue was discovered in the futures-intrusive crate before 0.4.0 for Rust. GenericMutexGuard allows cross-thread data races of non-Sync types.
ModificadaMedia (5.5)0.34%—Rust-lang Future-utils31/12/202017/6/2026
An issue was discovered in the futures-util crate before 0.3.2 for Rust. FuturesUnordered can lead to data corruption because Sync is mishandled.
ModificadaMedia (5.5)0.41%—Rust-lang Futures-task31/12/202017/6/2026
An issue was discovered in the futures-task crate before 0.3.5 for Rust. futures_task::noop_waker_ref allows a NULL pointer dereference.
AnalizadaAlta (7.8)0.50%—Rust-lang Futures-task31/12/202017/6/2026
An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation.
ModificadaMedia (4.7)0.26%—Rust-lang Future-utils31/12/202017/6/2026
An issue was discovered in the futures-util crate before 0.3.7 for Rust. MutexGuard::map can cause a data race for certain closure situations (in safe code).
ModificadaCrítica (9.8)3.6%—HP Futuresmart 3HP Futuresmart 416/10/201917/6/2026
HP LaserJet, PageWide, OfficeJet Enterprise, and LaserJet Managed Printers have a solution to check application signature that may allow potential execution of arbitrary code.
ModificadaMedia (5.9)3.2%—HP Futuresmart Firmware4/3/201617/6/2026
HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors.
ModificadaMedia (4.3)1.5%—Codefuture CF Image Hosting Script29/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is…
ModificadaMedia (5)2.2%—Future Nuke Php-nuke Platinum4/4/200816/6/2026
PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gpc.
ModificadaAlta (7.5)0.97%—Futurenuke PHP Nuke Platinum28/3/200816/6/2026
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary SQL commands via the p parameter to modules.php for the Forums module.
ModificadaMedia (6.8)2.3%—Futurenuke Platinum24/10/200716/6/2026
PHP remote file inclusion vulnerability in modules/Forums/favorites.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary PHP code via a URL in the nuke_bb_root_path parameter.
ModificadaAlta (10)13%—Futuresoft Tftp Server 200024/3/200716/6/2026
Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.
ModificadaAlta (7.5)1.1%—Future Internet28/12/200616/6/2026
Multiple SQL injection vulnerabilities in Future Internet allow remote attackers to execute arbitrary SQL commands via the (1) newsId or (2) categoryid parameter in a Portal.Showpage action in index.cfm, or (3) the langId parameter in index.cfm.
ModificadaMedia (6.8)1.8%—Future Internet28/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the categoryId parameter in a Portal.ShowPage action.
ModificadaAlta (7.5)1.2%—Futuretec E-calendar PRO21/11/200616/6/2026
Multiple SQL injection vulnerabilities in E-Calendar Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd (Password) fields in (a) admin/default.asp; or the (3) Event Title, (4) Location, or (5) Description field when making a search engine query in (b) search.asp. NOTE:…
ModificadaAlta (7.5)5.7%—Futuresoft Tftp Server Multithreaded14/9/200616/6/2026
Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constructing an absolute path name. NOTE: Some details are obtained…