Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | — | 22lixian Project 22lixian | 7/6/2018 | 17/6/2026 | 22lixian is a simple file server. 22lixian is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Crítica (9.8) | 2.9% | — | Alchemist-elixir Alchemist-server | 17/11/2017 | 17/6/2026 | Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious website can execute requests against an ephemeral port on localhost that are then evaluated as elixir code. | |
| Modificada | Alta (7.8) | 0.38% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+144 | 18/8/2017 | 17/6/2026 | A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path. | |
| Modificada | Alta (7.5) | 1.5% | — | Netflix Lemur | 9/8/2017 | 17/6/2026 | Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode. | |
| Modificada | Media (6.1) | 0.97% | — | Netflix Security Monkey | 26/3/2017 | 17/6/2026 | Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header. | |
| Modificada | Media (5.9) | 1.7% | — | Sleekxmpp Project SleekxmppSlixmpp Project SlixmppPoezio | 9/2/2017 | 17/6/2026 | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions… | |
| Modificada | Media (4.4) | 0.30% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+70 | 30/11/2016 | 17/6/2026 | A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be… | |
| Modificada | Baja (3.3) | 1.00% | — | Lixil MY Satis Genius Toilet | 16/4/2015 | 16/6/2026 | The LIXIL Corporation My SATIS Genius Toilet application for Android has a hardcoded Bluetooth PIN, which allows physically proximate attackers to trigger physical resource consumption (water or heat) or user discomfort. | |
| Modificada | Media (6.4) | 1.4% | — | Scalix WEB Access | 10/12/2014 | 17/6/2026 | XML external entity (XXE) vulnerability in Scalix Web Access 11.4.6.12377 and 12.2.0.14697 allows remote attackers to read arbitrary files and trigger requests to intranet servers via a crafted request. | |
| Modificada | Media (4.3) | 1.1% | — | Scalix WEB Access | 9/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the mail administration login panel in Scalix Web Access 11.4.6.12377 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.6) | 0.39% | — | Tedfelix Acpid2 | 29/8/2012 | 16/6/2026 | event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls. | |
| Modificada | Media (4.4) | 0.61% | 💥 Exploit | Tedfelix Acpid2 | 29/8/2012 | 16/6/2026 | samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands. | |
| Modificada | Media (4.3) | 1.7% | — | Ematia Elixir | 26/8/2012 | 16/6/2026 | Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the database. | |
| Modificada | Media (5) | 1.6% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted Open-PDU request that triggers incorrect DisplayString processing, a different vulnerability than… | |
| Modificada | Media (5) | 1.6% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (daemon crash) by establishing and closing a port-705 TCP connection, a different vulnerability than CVE-2012-1923. | |
| Modificada | Media (6.8) | 0.97% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to hijack the authentication of administrators for requests that cause a denial of service (stack consumption and daemon crash) via a malformed URL. | |
| Modificada | Media (4.3) | 1.8% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.1) | 38% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x store passwords in cleartext under adm_b_db\users\, which allows local users to obtain sensitive information by reading a database. | |
| Modificada | Alta (7.5) | 4.1% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | Buffer overflow in rn5auth.dll in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to execute arbitrary code via crafted authentication credentials. | |
| Modificada | Media (4.3) | 1.1% | — | Clixint Image Hosting Script DPI | 2/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter. | |
| Modificada | Baja (2.1) | 1.1% | 💥 Exploit | Tedfelix Acpid | 5/10/2011 | 16/6/2026 | acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls. | |
| Modificada | Alta (9.3) | 5.0% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 4/4/2011 | 16/6/2026 | Stack-based buffer overflow in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via a long string in an RTSP request. | |
| Modificada | Alta (10) | 4.1% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 4/4/2011 | 16/6/2026 | Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header. | |
| Modificada | Media (6.9) | 0.38% | — | Mistelix | 20/10/2010 | 16/6/2026 | Mistelix 0.31 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Alta (10) | 5.1% | — | Realnetworks Helix Mobile ServerRealnetworks Helix ServerRealnetworks Helix Server Mobile | 20/4/2010 | 16/6/2026 | Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted payload length. |