Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.59% | — | NO Future Posts Project NO Future Posts | 30/5/2022 | 17/6/2026 | The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed | |
| Modificada | Media (6.1) | 0.94% | — | Futurepress Epub.js | 17/1/2022 | 17/6/2026 | managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS. | |
| Modificada | Media (6.1) | 0.67% | — | HP Futuresmart 3HP Futuresmart 4 | 9/11/2021 | 17/6/2026 | A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link. | |
| Modificada | Alta (7.8) | 0.29% | — | HP Futuresmart 4 | 9/11/2021 | 17/6/2026 | A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution. | |
| Modificada | Crítica (9.8) | 12% | — | HP Futuresmart 3HP Futuresmart 4HP Futuresmart 5 | 3/11/2021 | 17/6/2026 | Certain HP Enterprise LaserJet, HP LaserJet Managed, HP Enterprise PageWide, HP PageWide Managed products may be vulnerable to potential buffer overflow. | |
| Modificada | Media (4.6) | 2.4% | — | HP Futuresmart 3HP Futuresmart 4HP Futuresmart 5 | 3/11/2021 | 17/6/2026 | Certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed printers may be vulnerable to potential information disclosure. | |
| Modificada | Media (4.3) | 0.47% | — | Tipsandtricks-hq FAR Future Expiry Header | 1/11/2021 | 17/6/2026 | The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |
| Modificada | Media (5.4) | 0.47% | — | HP Futuresmart 4HP Futuresmart 5 | 29/10/2021 | 17/6/2026 | Certain HP Enterprise LaserJet and PageWide MFPs may be vulnerable to stored cross site scripting (XSS). | |
| Modificada | Alta (8.1) | 0.77% | — | Tiny Future Project Tiny Future | 8/8/2021 | 17/6/2026 | An issue was discovered in the tiny_future crate before 0.4.0 for Rust. Future<T> does not have bounds on its Send and Sync traits. | |
| Modificada | Media (5.5) | 0.38% | — | Futures-intrusive Project Futures-intrusive | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-intrusive crate before 0.4.0 for Rust. GenericMutexGuard allows cross-thread data races of non-Sync types. | |
| Modificada | Media (5.5) | 0.34% | — | Rust-lang Future-utils | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-util crate before 0.3.2 for Rust. FuturesUnordered can lead to data corruption because Sync is mishandled. | |
| Modificada | Media (5.5) | 0.41% | — | Rust-lang Futures-task | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-task crate before 0.3.5 for Rust. futures_task::noop_waker_ref allows a NULL pointer dereference. | |
| Analizada | Alta (7.8) | 0.50% | — | Rust-lang Futures-task | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation. | |
| Modificada | Media (4.7) | 0.26% | — | Rust-lang Future-utils | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-util crate before 0.3.7 for Rust. MutexGuard::map can cause a data race for certain closure situations (in safe code). | |
| Modificada | Crítica (9.8) | 3.6% | — | HP Futuresmart 3HP Futuresmart 4 | 16/10/2019 | 17/6/2026 | HP LaserJet, PageWide, OfficeJet Enterprise, and LaserJet Managed Printers have a solution to check application signature that may allow potential execution of arbitrary code. | |
| Modificada | Media (5.9) | 3.2% | — | HP Futuresmart Firmware | 4/3/2016 | 17/6/2026 | HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | Codefuture CF Image Hosting Script | 29/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is… | |
| Modificada | Media (5) | 2.2% | — | Future Nuke Php-nuke Platinum | 4/4/2008 | 16/6/2026 | PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gpc. | |
| Modificada | Alta (7.5) | 0.97% | — | Futurenuke PHP Nuke Platinum | 28/3/2008 | 16/6/2026 | SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary SQL commands via the p parameter to modules.php for the Forums module. | |
| Modificada | Media (6.8) | 2.3% | — | Futurenuke Platinum | 24/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in modules/Forums/favorites.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary PHP code via a URL in the nuke_bb_root_path parameter. | |
| Modificada | Alta (10) | 13% | — | Futuresoft Tftp Server 2000 | 24/3/2007 | 16/6/2026 | Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812. | |
| Modificada | Alta (7.5) | 1.1% | — | Future Internet | 28/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Future Internet allow remote attackers to execute arbitrary SQL commands via the (1) newsId or (2) categoryid parameter in a Portal.Showpage action in index.cfm, or (3) the langId parameter in index.cfm. | |
| Modificada | Media (6.8) | 1.8% | — | Future Internet | 28/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the categoryId parameter in a Portal.ShowPage action. | |
| Modificada | Alta (7.5) | 1.2% | — | Futuretec E-calendar PRO | 21/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in E-Calendar Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd (Password) fields in (a) admin/default.asp; or the (3) Event Title, (4) Location, or (5) Description field when making a search engine query in (b) search.asp. NOTE:… | |
| Modificada | Alta (7.5) | 5.7% | — | Futuresoft Tftp Server Multithreaded | 14/9/2006 | 16/6/2026 | Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constructing an absolute path name. NOTE: Some details are obtained… |