Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.4%—Intersectalliance System Intrusion Analysis AND Reporting Environment14/5/201416/6/2026
Cross-site scripting (XSS) vulnerability in the events page in the System iNtrusion Analysis and Reporting Environment (SNARE) for Linux agent before 1.7.0 allows remote attackers to inject arbitrary web script or HTML via a logged shell command.
ModificadaAlta (10)7.4%—HP Distributed Computing EnvironmentHp-ux5/4/201216/6/2026
Distributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
ModificadaMedia (6)1.8%—HP Virtual Server Environment3/5/201116/6/2026
Unspecified vulnerability in HP Virtual Server Environment before 6.3 allows remote authenticated users to gain privileges via unknown vectors.
ModificadaMedia (5)2.2%—HP Virtual Server Environment28/10/201016/6/2026
Unspecified vulnerability in HP Virtual Server Environment before 6.2 allows remote attackers to read arbitrary files via unknown vectors.
ModificadaAlta (7.5)5.7%—SUN Java Runtime EnvironmentSUN Java SE Development KIT25/3/200916/6/2026
Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer…
ModificadaAlta (7.5)1.7%—Lxde GpicviewLxde Lightweight X11 Desktop Environment4/9/200816/6/2026
src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.
ModificadaMedia (4.6)0.34%—Lxde Lightweight X11 Desktop Environment3/9/200816/6/2026
src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.
ModificadaMedia (5.1)2.7%💥 ExploitInteract Learning Community Environment Interact30/8/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] parameter in (a) admin/autoprompter.php and (b) includes/common.inc.php, and the (2) CONFIG[LANGUAGE_CPATH] parameter in (c)…
ModificadaAlta (7.2)0.35%—SUN Storage Automated Diagnostic Environment2/6/200616/6/2026
A package component in Sun Storage Automated Diagnostic Environment (StorADE) 2.4 uses world-writable permissions for certain critical files and directories, which allows local users to gain privileges.
ModificadaAlta (10)2.0%—Eric Integrated Development Environment27/9/200516/6/2026
Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit."
ModificadaAlta (7.5)3.0%—Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+1827/4/200516/6/2026
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
ModificadaAlta (7.2)0.41%—IBM Parallel Environment31/12/200416/6/2026
Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.
ModificadaAlta (10)11%—Open Group CDE Common Desktop EnvironmentXI Graphics DextopIBM AIX4/5/200416/6/2026
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.
ModificadaMedia (4.6)0.41%—Freebsd Advanced Intrusion Detection Environment31/12/200216/6/2026
The default aide.conf file in Advanced Intrusion Detection Environment (AIDE) before 0.7_1 on FreeBSD before 2002-08-28 does not properly check subdirectories, which could allow local users to bypass detection.
ModificadaMedia (5)6.9%—Caldera Openlinux ServerCaldera Openlinux WorkstationRedhat Pre-execution EnvironmentHP Secure OS4/10/200216/6/2026
Preboot eXecution Environment (PXE) server allows remote attackers to cause a denial of service (crash) via certain DHCP packets from Voice-Over-IP (VOIP) phones.
ModificadaAlta (10)86%💥 ExploitOpen Group CDE Common Desktop Environment6/12/200116/6/2026
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.
Orbitaley — Vulnerabilidades