Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.8% | — | Shutterstock Ntfserver | 29/5/2018 | 17/6/2026 | ntfserver is a Network Testing Framework Server. ntfserver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in… | |
| Modificada | Crítica (9.8) | 3.0% | — | Shutterstock Clone Project Shutterstock Clone | 13/12/2017 | 17/6/2026 | FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter. | |
| Modificada | Alta (7.8) | 6.7% | — | Shutter-project Shutter | 29/12/2016 | 17/6/2026 | /usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Run a plugin" action. | |
| Modificada | Alta (7.8) | 2.5% | — | Shutter-project Shutter | 29/12/2016 | 17/6/2026 | App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action. | |
| Modificada | Media (4.3) | 0.93% | — | Tenfourzero Shutter | 17/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in tenfourzero Shutter 0.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenfourzero Shutter | 17/8/2014 | 17/6/2026 | SQL injection vulnerability in lib/admin.php in tenfourzero Shutter 0.1.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.99% | — | Tenfourzero Shutter | 16/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) albumID, (2) tagID, and (3) photoID parameters to index.html. |