Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | Intersectalliance System Intrusion Analysis AND Reporting Environment | 14/5/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the events page in the System iNtrusion Analysis and Reporting Environment (SNARE) for Linux agent before 1.7.0 allows remote attackers to inject arbitrary web script or HTML via a logged shell command. | |
| Modificada | Alta (10) | 7.4% | — | HP Distributed Computing EnvironmentHp-ux | 5/4/2012 | 16/6/2026 | Distributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Media (6) | 1.8% | — | HP Virtual Server Environment | 3/5/2011 | 16/6/2026 | Unspecified vulnerability in HP Virtual Server Environment before 6.3 allows remote authenticated users to gain privileges via unknown vectors. | |
| Modificada | Media (5) | 2.2% | — | HP Virtual Server Environment | 28/10/2010 | 16/6/2026 | Unspecified vulnerability in HP Virtual Server Environment before 6.2 allows remote attackers to read arbitrary files via unknown vectors. | |
| Modificada | Alta (7.5) | 5.7% | — | SUN Java Runtime EnvironmentSUN Java SE Development KIT | 25/3/2009 | 16/6/2026 | Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer… | |
| Modificada | Alta (7.5) | 1.7% | — | Lxde GpicviewLxde Lightweight X11 Desktop Environment | 4/9/2008 | 16/6/2026 | src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. | |
| Modificada | Media (4.6) | 0.34% | — | Lxde Lightweight X11 Desktop Environment | 3/9/2008 | 16/6/2026 | src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file. | |
| Modificada | Media (5.1) | 2.7% | 💥 Exploit | Interact Learning Community Environment Interact | 30/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] parameter in (a) admin/autoprompter.php and (b) includes/common.inc.php, and the (2) CONFIG[LANGUAGE_CPATH] parameter in (c)… | |
| Modificada | Alta (7.2) | 0.35% | — | SUN Storage Automated Diagnostic Environment | 2/6/2006 | 16/6/2026 | A package component in Sun Storage Automated Diagnostic Environment (StorADE) 2.4 uses world-writable permissions for certain critical files and directories, which allows local users to gain privileges. | |
| Modificada | Alta (10) | 2.0% | — | Eric Integrated Development Environment | 27/9/2005 | 16/6/2026 | Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit." | |
| Modificada | Alta (7.5) | 3.0% | — | Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+18 | 27/4/2005 | 16/6/2026 | The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities. | |
| Modificada | Alta (7.2) | 0.41% | — | IBM Parallel Environment | 31/12/2004 | 16/6/2026 | Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code. | |
| Modificada | Alta (10) | 11% | — | Open Group CDE Common Desktop EnvironmentXI Graphics DextopIBM AIX | 4/5/2004 | 16/6/2026 | Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet. | |
| Modificada | Media (4.6) | 0.41% | — | Freebsd Advanced Intrusion Detection Environment | 31/12/2002 | 16/6/2026 | The default aide.conf file in Advanced Intrusion Detection Environment (AIDE) before 0.7_1 on FreeBSD before 2002-08-28 does not properly check subdirectories, which could allow local users to bypass detection. | |
| Modificada | Media (5) | 6.9% | — | Caldera Openlinux ServerCaldera Openlinux WorkstationRedhat Pre-execution EnvironmentHP Secure OS | 4/10/2002 | 16/6/2026 | Preboot eXecution Environment (PXE) server allows remote attackers to cause a denial of service (crash) via certain DHCP packets from Voice-Over-IP (VOIP) phones. | |
| Modificada | Alta (10) | 86% | 💥 Exploit | Open Group CDE Common Desktop Environment | 6/12/2001 | 16/6/2026 | Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands. |