Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.3%—EMC Sourceone Email Supervisor18/10/201517/6/2026
Cross-site scripting (XSS) vulnerability in Reviewer in EMC SourceOne Email Supervisor before 7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)2.9%—EMC Sourceone Email Supervisor18/10/201517/6/2026
Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to obtain access via a brute-force approach.
ModificadaAlta (9.4)2.8%—Cisco Integrated Management Controller SupervisorCisco Unified Computing System Director4/9/201517/6/2026
The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625.
ModificadaAlta (9)2.9%—Cisco Telepresence Advanced Media GatewayCisco Telepresence IP GatewayCisco Telepresence IP VCR 1.0 ConverterCisco Telepresence IP VCR 2.4+625/5/201517/6/2026
The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software before 4.4(3.54) and 4.5…
ModificadaMedia (4.3)1.6%—Mywebsiteadvisor Simple Security15/1/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) datefilter parameter in the access_log page to wp-admin/users.php or (2) simple_security_ip_blacklist[] parameter…
ModificadaMedia (5.4)0.27%—Pocketmags PC Advisor19/10/201417/6/2026
The PC Advisor (aka com.triactivemedia.pcadvisor) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Homeadvisor Mobile2/10/201417/6/2026
The HomeAdvisor Mobile (aka com.servicemagic.consumer) application 3.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.4)0.54%—Redhat Enterprise Virtualization Hypervisor27/12/201316/6/2026
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
ModificadaAlta (7.8)1.3%—Cisco Telepresence Supervisor MSE 8050 SoftwareCisco Telepresence Supervisor MSE 805016/5/201316/6/2026
Cisco TelePresence Supervisor MSE 8050 before 2.3(1.31) allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing TCP connections at a high rate, aka Bug IDs CSCuf76076 and CSCuf79763.
ModificadaMedia (5)1.2%—Tripadvisor26/1/201316/6/2026
The TripAdvisor app 6.6 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaMedia (5)1.8%—EMC Data Protection Advisor26/12/201216/6/2026
Directory traversal vulnerability in the Web UI in EMC Data Protection Advisor (DPA) 5.6 through SP1, 5.7 through SP1, and 5.8 through SP4 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (5)1.1%—IBM Remote Supervisor Adapter II Firmware25/9/201216/6/2026
IBM Remote Supervisor Adapter II firmware for System x3650, x3850 M2, and x3950 M2 1.13 and earlier generates weak RSA keys, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.
ModificadaMedia (5)3.2%💥 ExploitEMC Data Protection Advisor20/4/201216/6/2026
Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (infinite loop) via a negative 64-bit value in a certain size field.
ModificadaAlta (7.8)8.6%💥 ExploitEMC Data Protection Advisor20/4/201216/6/2026
The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.
ModificadaMedia (5)7.4%💥 ExploitCarel Plantvisor16/9/201116/6/2026
Directory traversal vulnerability in CarelDataServer.exe in Carel PlantVisor 2.4.4 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.
ModificadaMedia (5.7)0.99%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Virtualization Hypervisor31/8/201116/6/2026
The Generic Receive Offload (GRO) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux 5 and 2.6.32 on Red Hat Enterprise Linux 6, as used in Red Hat Enterprise Virtualization (RHEV) Hypervisor and other products, allows remote attackers to cause a denial of service via crafted VLAN packets that are…
ModificadaBaja (2.1)0.32%—EMC Data Protection Advisor1/8/201116/6/2026
EMC Data Protection Advisor before 5.8.1 places cleartext account credentials in the DPA configuration file in unspecified circumstances, which might allow local users to obtain sensitive information by reading this file.
ModificadaAlta (7.2)1.5%—Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+3113/4/201116/6/2026
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different…
ModificadaAlta (7.2)0.38%—EMC Data Protection Advisor CollectorOracle Solaris Sparc28/3/201116/6/2026
EMC Data Protection Advisor Collector 5.7 and 5.7.1 on Solaris SPARC platforms uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
ModificadaBaja (2.1)0.37%—Redhat Enterprise Virtualization Hypervisor24/6/201016/6/2026
Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks…
ModificadaAlta (7.1)1.9%—Cisco Route Switch ProcessorCisco Supervisor Engine27/3/200816/6/2026
Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link, allows remote attackers to cause a denial of service (blocked queue, device…
ModificadaAlta (7.5)0.99%💥 ExploitPopscript.com Expert Advisor18/7/200716/6/2026
SQL injection vulnerability in index.php in Expert Advisor allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5)2.1%—Palm OSHandspring Visor22/10/200116/6/2026
Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruption) by sending a large or crafted SMS image.
ModificadaBaja (2.1)0.37%—Wquinn Diskadvisor19/12/200023/9/2026
WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.
ModificadaMedia (4.6)0.46%—Wquinn Quotaadvisor19/12/200023/9/2026
WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.
Orbitaley — Vulnerabilidades