Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

325 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.1%💥 ExploitScriptbrasil Taboada Macronews13/1/201517/6/2026
SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
ModificadaBaja (2.1)0.43%—Bcron Project Bcron Exec29/9/201416/6/2026
bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.
ModificadaMedia (4.3)2.0%—Wokamoto Wp-cron Dashboard3/1/201417/6/2026
Cross-site scripting (XSS) vulnerability in the WP-Cron Dashboard plugin 1.1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the procname parameter to wp-admin/tools.php.
ModificadaMedia (4.3)1.3%—Fedorahosted Cronie9/4/201316/6/2026
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
ModificadaBaja (3.5)0.94%—63reasons Supercron20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the SuperCron module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)0.98%💥 ExploitMicronetsoft Rental Property Website8/10/201116/6/2026
SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter.
ModificadaAlta (7.5)0.98%💥 ExploitMicronetsoft RV Dealer Website8/10/201116/6/2026
SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter.
ModificadaAlta (7.5)0.96%💥 ExploitMicronetsoft RV Dealer Website1/12/201016/6/2026
Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp.
ModificadaBaja (1.9)0.35%—Thibault Godouet Fcron5/3/201016/6/2026
fcrontab in fcron before 3.0.5 allows local users to read arbitrary files via a symlink attack on an unspecified file.
ModificadaBaja (3.3)0.35%—Fedorahosted CroniePaul Vixie Vixie Cron25/2/201016/6/2026
The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.
ModificadaMedia (4.3)1.3%💥 ExploitMicronet Network Access Controller Sp19108/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModificadaMedia (4.6)0.30%—Inotify Incron8/10/200916/6/2026
incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table.
ModificadaAlta (7.5)2.3%💥 ExploitMinbank Micronation Banking System30/1/200916/6/2026
Multiple PHP remote file inclusion vulnerabilities in Micronation Banking System (minba) 1.5.0 allow remote attackers to execute arbitrary PHP code via a URL in the minsoft_path parameter to (1) utdb_access.php and (2) utgn_message.php in utility/.
ModificadaMedia (5)1.6%—Acronis True Image Echo Server13/8/200816/6/2026
Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)5.6%💥 ExploitAcronis Snap Deploy20/3/200816/6/2026
Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.
ModificadaMedia (5)7.6%💥 ExploitAcronis Snap Deploy20/3/200816/6/2026
The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of service (crash) via an incomplete TFTP request, which triggers a NULL pointer dereference.
ModificadaMedia (5)2.5%—Acronis True ImageAcronis True Image Windows Agent10/3/200816/6/2026
Acronis True Image Windows Agent 1.0.0.54 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a malformed packet to port 9876, which triggers a NULL pointer dereference.
ModificadaMedia (5)1.7%—Acronis True Image10/3/200816/6/2026
Acronis True Image Group Server 1.5.19.191 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a packet with an invalid length field, which causes an out-of-bounds read.
ModificadaAlta (10)2.6%—Micronews22/1/200816/6/2026
MicroNews allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin.php.
ModificadaBaja (2.1)0.38%—Paul Vixie Vixie Cron18/4/200716/6/2026
Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.
ModificadaAlta (7.5)3.6%💥 ExploitCronosys Cadre PHP Framework3/2/200716/6/2026
PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter.
ModificadaBaja (2.1)0.33%—Inotify Incron31/1/200716/6/2026
Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to "access rights to watched files."
ModificadaAlta (7.5)1.1%💥 ExploitCodemonkeyx Acronym MOD31/12/200616/6/2026
SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.2)0.56%—Paul Vixie Vixie Cron25/5/200616/6/2026
do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process limits as defined in…
ModificadaMedia (5)1.6%—Thibault Godouet Fcron7/2/200616/6/2026
convert-fcrontab in Fcron 2.9.5 and 3.0.0 allows remote attackers to create or overwrite arbitrary files via ".." sequences and a symlink attack on the temporary file that is used during conversion.
Orbitaley — Vulnerabilidades