Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.38% | — | Gdm-guest-session Project Gdm-guest-sessionCanonical Ubuntu Linux | 22/5/2014 | 16/6/2026 | gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT from CVE-2012-0943 per ADT1/ADT2 due to different codebases and affected… | |
| Modificada | Media (5) | 1.6% | — | Checkpoint Session Authentication Agent | 26/1/2014 | 17/6/2026 | Check Point Session Authentication Agent allows remote attackers to obtain sensitive information (user credentials) via unspecified vectors. | |
| Modificada | Alta (10) | 2.8% | — | Siemens Openscape Session Border ControllerSiemens Enterprise Openscape Branch | 18/7/2013 | 16/6/2026 | core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to execute arbitrary commands via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.4% | — | Siemens Openscape Session Border ControllerSiemens Enterprise Openscape Branch | 18/7/2013 | 16/6/2026 | core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 0.93% | — | Siemens Openscape Session Border ControllerSiemens Enterprise Openscape Branch | 18/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in core/handleTw.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.4% | — | Siemens Openscape Session Border ControllerSiemens Enterprise Openscape Branch | 18/7/2013 | 16/6/2026 | core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to obtain sensitive server and statistics information via unspecified vectors. | |
| Modificada | Media (5.9) | 84% | — | Oracle Communications Application Session ControllerOracle Http ServerOracle Integrated Lights OUT Manager FirmwareFujitsu Sparc Enterprise M3000 Firmware+12 | 15/3/2013 | 16/6/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext. | |
| Modificada | Alta (8.1) | 17% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxVmware ESXAvaya Aura Communication Manager+6 | 30/9/2010 | 16/6/2026 | The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked… | |
| Modificada | Media (5.5) | 0.42% | — | Linux KernelCanonical Ubuntu LinuxOpensuseSuse Linux Enterprise Desktop+9 | 21/9/2010 | 16/6/2026 | The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the… | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelVmware ESXCanonical Ubuntu LinuxDebian Linux+11 | 8/9/2010 | 16/6/2026 | The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by… | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelVmware ESXAvaya Aura Communication ManagerAvaya Aura Presence Services+5 | 8/9/2010 | 16/6/2026 | Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Obsession-design Image-gallery | 16/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter. | |
| Modificada | Alta (7.1) | 0.44% | — | Linux KernelRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+14 | 16/11/2009 | 16/6/2026 | The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. | |
| Modificada | Alta (7.8) | 2.3% | — | Cisco Session Border Controller | 5/3/2009 | 16/6/2026 | Unspecified vulnerability in the Session Border Controller (SBC) before 3.0(2) for Cisco 7600 series routers allows remote attackers to cause a denial of service (SBC card reload) via crafted packets to TCP port 2000. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Myphpscripts Login Session | 6/1/2009 | 16/6/2026 | myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Myphpscripts Login Session | 6/1/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in login.php in myPHPscripts Login Session 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ls_user and (2) ls_email parameters (aka the User form) in an ls_register action. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (10) | 69% | 💥 Exploit | Juniper Session AND Resource ControlJuniper SRC PE | 10/6/2008 | 16/6/2026 | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7)… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Skinny Client Control Protocol (sccp) FirmwareCisco Session Initiation Protocol (sip) Firmware | 15/2/2008 | 16/6/2026 | Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a long ICMP echo request (ping) packet. | |
| Modificada | Alta (10) | 5.4% | — | Cisco Skinny Client Control Protocol (sccp) FirmwareCisco Session Initiation Protocol (sip) Firmware | 15/2/2008 | 16/6/2026 | Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response. | |
| Modificada | Alta (10) | 5.4% | — | Cisco Skinny Client Control Protocol (sccp) FirmwareCisco Session Initiation Protocol (sip) Firmware | 15/2/2008 | 16/6/2026 | Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command. | |
| Modificada | Alta (10) | 5.4% | — | Cisco Skinny Client Control Protocol (sccp) FirmwareCisco Session Initiation Protocol (sip) Firmware | 15/2/2008 | 16/6/2026 | Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Skinny Client Control Protocol (sccp) FirmwareCisco Session Initiation Protocol (sip) Firmware | 15/2/2008 | 16/6/2026 | The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request. | |
| Modificada | Alta (9.3) | 2.9% | — | Cisco Skinny Client Control Protocol (sccp) FirmwareCisco Session Initiation Protocol (sip) Firmware | 15/2/2008 | 16/6/2026 | Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message. | |
| Modificada | Alta (7.5) | 1.7% | — | Sherzod Ruzmetov CGI Session | 19/3/2006 | 16/6/2026 | CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session keys, by viewing the files. | |
| Modificada | Media (5) | 1.3% | — | Sherzod Ruzmetov CGI Session | 19/3/2006 | 16/6/2026 | CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite. |