Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 6.1% | — | Powerdns Authoritative ServerPowerdns | 8/8/2008 | 16/6/2026 | PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217. | |
| Modificada | Media (4.3) | 1.9% | — | RSA Keon Registration Authority WEB Interface | 29/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON Registration Authority Web Interface 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.6) | 0.21% | — | RSA Keon Certificate Authority Manager | 26/9/2006 | 16/6/2026 | RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity… | |
| Modificada | Media (5.1) | 3.1% | 💥 Exploit | Thorcms | 28/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions_cms.php in THoRCMS 1.3.1 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Thorcms | 28/6/2006 | 16/6/2026 | SQL injection vulnerability in cms_admin.php in THoRCMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via multiple unspecified parameters, such as the add_link_mid parameter. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information. | |
| Modificada | Media (4.6) | 0.38% | — | Curtis Hawthorne Tn3270 Resource Gateway | 23/12/2005 | 16/6/2026 | Format string vulnerability in TN3270 Resource Gateway 1.1.0 allows local users to cause a denial of service and possibly execute arbitrary code via format string specifiers in syslog function calls. | |
| Modificada | Baja (2.1) | 5.3% | — | Entrust Authority Security Manager | 3/2/2004 | 16/6/2026 | Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations. | |
| Modificada | Media (5) | 1.7% | — | Thorsten Korner 123tkshop | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null character in the $designNo variable, which is part of an "include" function call. | |
| Modificada | Alta (7.5) | 1.2% | — | Thorsten Korner 123tkshop | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Authoria | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command parameter. | |
| Modificada | Alta (7.5) | 4.1% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6)… | |
| Modificada | Alta (7.5) | 1.6% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which… | |
| Modificada | Alta (7.5) | 2.5% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path. | |
| Modificada | Alta (7.5) | 2.3% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | RAY Chan WWW Authorization Gateway | 8/7/1998 | 16/6/2026 | Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter. |