Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 1.9% | — | HP 3com RouterHP 5500-24g-4sfp HI Switch With 2 Interface SlotsHP 5500-24g-poe EI SwitchHP 5500-24g-poe SI Switch+13 | 12/8/2013 | 16/6/2026 | The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the… | |
| Modificada | Alta (7.5) | 79% | 💥 Exploit | Oracle Fujitsu M10 FirmwareIntelligent Platform Management Interface | 8/7/2013 | 16/6/2026 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC. | |
| Modificada | Media (5) | 1.4% | — | IBM Sterling Connect Direct User Interface | 21/6/2013 | 16/6/2026 | The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | |
| Modificada | Baja (1.9) | 0.32% | — | IBM Sterling Connect Direct User Interface | 21/6/2013 | 16/6/2026 | The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the screen of an unattended workstation. | |
| Modificada | Media (4.3) | 7.2% | 💥 Exploit | Solarwinds IP Address Manager WEB InterfaceSolarwinds Orion Network Performance Monitor | 31/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field. | |
| Modificada | Media (6.9) | 0.36% | — | SAP Graphical User Interface | 6/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file. NOTE: some of these details are… | |
| Modificada | Alta (8.5) | 4.7% | — | Osisoft PI OPC DA Interface | 20/7/2012 | 16/6/2026 | Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by sending packet data during the processing of messages associated with OPC items. | |
| Modificada | Media (5) | 5.7% | 💥 Exploit | Dream-multimedia-tv Enigma2 Webinterface | 8/2/2012 | 16/6/2026 | Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary files via a full pathname in the file parameter. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Dream-multimedia-tv Enigma2 Webinterface | 8/2/2012 | 16/6/2026 | Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Citrix WEB Interface | 9/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454. | |
| Modificada | Media (5) | 1.2% | — | Cisco Unified Videoconferencing System 5110 FirmwareCisco Unified Videoconferencing System 5115 FirmwareCisco Unified Videoconferencing System 5110Cisco Unified Videoconferencing System 5115+10 | 22/11/2010 | 16/6/2026 | Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) improperly use cookies for web-interface… | |
| Modificada | Media (6.4) | 1.2% | — | Cisco Unified Videoconferencing System 5110 FirmwareCisco Unified Videoconferencing System 5115 FirmwareCisco Unified Videoconferencing System 5110Cisco Unified Videoconferencing System 5115+10 | 22/11/2010 | 16/6/2026 | The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) uses predictable… | |
| Modificada | Alta (8.5) | 2.9% | — | Cisco Unified Videoconferencing System 5110 FirmwareCisco Unified Videoconferencing System 5115 FirmwareCisco Unified Videoconferencing System 5110Cisco Unified Videoconferencing System 5115+10 | 22/11/2010 | 16/6/2026 | goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 and 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, and Unified… | |
| Modificada | Media (4.3) | 1.1% | — | Citrix WEB Interface | 14/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6, 5.0, and 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.7% | — | Citrix WEB Interface | 8/6/2009 | 16/6/2026 | The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface session. NOTE: the attacker must also have valid… | |
| Modificada | Alta (7.8) | 2.8% | 💥 Exploit | Interface-medien Ibase | 25/2/2009 | 16/6/2026 | Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | |
| Modificada | Alta (7.8) | 1.9% | — | Intel Network Interface Controller | 16/6/2008 | 16/6/2026 | Unspecified vulnerability in the e1000g driver in Sun Solaris 10 and OpenSolaris before snv_93 allows remote attackers to cause a denial of service (network connectivity loss) via unknown vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Aeries Browser Interface | 24/12/2007 | 16/6/2026 | SQL injection vulnerability in the forget password section (LostPwd.asp) in Eagle Software Aeries Browser Interface (ABI) 3.7.9.17 allows remote attackers to execute arbitrary SQL commands via the EmailAddress parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.3% | — | Citrix WEB Interface | 20/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | RSA Keon Registration Authority WEB Interface | 29/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON Registration Authority Web Interface 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 24% | — | Microsoft OfficeMicrosoft Office Multilingual User Interface PackMicrosoft Office Proofing ToolsMicrosoft Project Multilingual User Interface Pack+1 | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed. | |
| Modificada | Alta (10) | 7.9% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | Multiple buffer overflows in Winamp Web Interface (Wawi) 7.5.13 and earlier (1) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an (a) long username or a (b) crafted packet to the FindBasicAuth function in security.cpp, related to the /browse URI; and… | |
| Modificada | Baja (3.5) | 1.3% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | Directory traversal vulnerability in the Browse function (/browse URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to list arbitrary directories via URL encoded backslashes ("%2F") in the path parameter. | |
| Modificada | Baja (3.5) | 1.3% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target… | |
| Modificada | Baja (3.5) | 1.4% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | The CControl::Download function (/dl URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to download arbitrary file types under the root via a trailing "." (dot) in a filename in the file parameter, related to erroneous behavior of the IsWinampFile function. |