Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

238 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.1%—Extreme CMS20/11/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in admin/options.php in Extreme CMS 0.9, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) bg1, (2) bg2, (3) text, or (4) size parameters. NOTE: the provenance of this information is unknown; details are obtained from…
ModificadaMedia (6.8)1.2%—Extreme CMS20/11/200616/6/2026
admin/options.php in Extreme CMS 0.9, and possibly earlier, does not require authentication, which might allow remote attackers to conduct unauthorized activities. NOTE: this issue can be combined with another vulnerability to expand the scope of a cross-site scripting (XSS) attack without authentication. NOTE: the…
ModificadaMedia (5.1)9.9%💥 ExploitXMB Software Extreme Message Board17/8/200616/6/2026
Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is…
ModificadaMedia (5)1.7%—Apple Airport ExpressApple Airport Extreme31/12/200516/6/2026
The network interface for Apple AirPort Express 6.x before Firmware Update 6.3, and AirPort Extreme 5.x before Firmware Update 5.7, allows remote attackers to cause a denial of service (unresponsive interface) via malformed packets.
ModificadaMedia (5)1.2%—Phpbb Styles Phpbb Extreme Styles8/12/200516/6/2026
xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter.
ModificadaMedia (5)1.5%—Phpbb Styles Extreme Styles Phpbb Module8/12/200516/6/2026
Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter.
ModificadaMedia (4.3)1.8%💥 ExploitExtreme Corporate Extreme Search3/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in extremesearch.php in Extreme Search Corporate Edition 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
ModificadaMedia (4.6)0.85%—Extremenetworks Extremeware XOS19/5/200516/6/2026
Unknown vulnerability in Extreme BlackDiamond 10808 and 8800 switches running ExtremeWare XOS 11.1 before 11.1.3.3, 11.0 before 11.0.2.4, and 10.x allows remote authenticated users to execute arbitrary commands.
ModificadaMedia (5)1.6%—Apple Airport ExpressApple Airport Extreme2/5/200516/6/2026
Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs.
ModificadaAlta (10)3.1%—Esesix Thintune ExtremeEsesix Thintune LEsesix Thintune MEsesix Thintune Mobile+331/12/200416/6/2026
radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain access.
ModificadaMedia (4.6)0.36%—Esesix Thintune ExtremeEsesix Thintune LEsesix Thintune MEsesix Thintune Mobile+331/12/200416/6/2026
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.
ModificadaMedia (4.6)0.44%—Esesix Thintune ExtremeEsesix Thintune LEsesix Thintune MEsesix Thintune Mobile+331/12/200416/6/2026
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshell.
ModificadaMedia (5)1.4%—Esesix Thintune ExtremeEsesix Thintune LEsesix Thintune MEsesix Thintune Mobile+324/7/200416/6/2026
The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.
Orbitaley — Vulnerabilidades