Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.7%—Clickhouse15/8/201917/6/2026
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.
ModificadaCrítica (9.8)3.4%—Clickhouse15/8/201917/6/2026
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.
ModificadaCrítica (9.8)1.8%—Clickhouse15/8/201917/6/2026
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
ModificadaAlta (7.5)1.7%—Clickhouse15/8/201917/6/2026
ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server.
ModificadaAlta (8.8)0.72%—Clickhouse15/8/201917/6/2026
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks.
ModificadaCrítica (9.8)1.6%—Enghouse Contact Center\14/5/201917/6/2026
ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka…
ModificadaAlta (7.5)2.2%—Housegate House Gate13/2/201917/6/2026
Directory traversal vulnerability in HOUSE GATE App for iOS 1.7.8 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaAlta (7.8)2.0%—Antennahouse Office Server Document Converter11/7/201817/6/2026
In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution.
ModificadaAlta (7.8)2.1%—Antennahouse Office Server Document Converter11/7/201817/6/2026
An exploitable out-of-bounds write exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution. This…
ModificadaAlta (7.8)2.5%—Antennahouse Office Server Document Converter11/7/201817/6/2026
An exploitable stack-based buffer overflow exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted Microsoft Word (DOC) document can lead to a stack-based buffer overflow, resulting in remote code…
ModificadaAlta (7.8)2.5%—Antennahouse Office Server Document Converter11/7/201817/6/2026
In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution. This vulnerability occurs in the `putShapeProperty` method.
ModificadaAlta (7.8)1.6%—Antennahouse Office Server Document Converter11/7/201817/6/2026
In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution. This vulnerability occurs in the `vbgetfp` method.
ModificadaAlta (7.8)2.5%—Antennahouse Office Server Document Converter11/7/201817/6/2026
An exploitable heap corruption exists in the PowerPoint document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted PowerPoint (PPT) document can lead to heap corruption, resulting in remote code execution.
ModificadaAlta (7.5)1.1%—Maxhouse Project Maxhouse9/7/201817/6/2026
The mintToken function of a smart contract implementation for MaxHouse, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.0%—Ecogreenhouse Project Ecogreenhouse9/7/201817/6/2026
The mintToken function of a smart contract implementation for ecogreenhouse, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.4)1.00%—Swhouse Istar Ultra Firmware31/12/201717/6/2026
A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the…
ModificadaMedia (6.1)0.96%—SAP Business Warehouse Universal Data Integration12/12/201717/6/2026
Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient encoding of user controlled inputs.
ModificadaMedia (6.1)1.0%—Oracle Retail Warehouse Management System24/4/201717/6/2026
Vulnerability in the Oracle Retail Warehouse Management System component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 13.2, 14.0 and 15.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail…
ModificadaAlta (8.1)1.2%—Tollgrade Lighthouse SMS15/7/201617/6/2026
Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and read or change parameter values, via a direct request.
ModificadaMedia (5.3)1.3%—Tollgrade Lighthouse SMS15/7/201617/6/2026
Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of attempts.
ModificadaAlta (7.5)2.9%—Enghousenetworks Lighthouse SMS15/7/201617/6/2026
Tollgrade LightHouse SMS before 5.1 patch 3 allows remote attackers to bypass authentication and restart the software via unspecified vectors.
ModificadaMedia (6.1)0.91%—Tollgrade Smartgrid Lighthouse Sensor Management System13/2/201617/6/2026
Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)2.1%—Tollgrade Smartgrid Lighthouse Sensor Management System13/2/201617/6/2026
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote authenticated users to change arbitrary passwords via unspecified vectors.
ModificadaMedia (5.3)1.2%—Tollgrade Smartgrid Lighthouse Sensor Management System13/2/201617/6/2026
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username information via unspecified vectors.
ModificadaAlta (8.8)0.60%—Tollgrade Smartgrid Lighthouse Sensor Management System13/2/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to hijack the authentication of arbitrary users.