Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Nexusphp | 24/8/2017 | 17/6/2026 | SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Nexusphp | 24/8/2017 | 17/6/2026 | SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Nexusphp | 21/8/2017 | 17/6/2026 | NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action. | |
| Modificada | Crítica (9.8) | 1.4% | — | Nexusphp Project Nexusphp | 18/8/2017 | 17/6/2026 | SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter. | |
| Modificada | Media (6.1) | 0.68% | — | Nexusphp Project Nexusphp | 18/8/2017 | 17/6/2026 | Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php. | |
| Modificada | Crítica (9.8) | 1.3% | — | Nexusphp Project Nexusphp | 17/8/2017 | 17/6/2026 | SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or parameter. | |
| Modificada | Crítica (9.8) | 1.4% | — | Nexusphp Project Nexusphp | 17/8/2017 | 17/6/2026 | SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter. | |
| Modificada | Crítica (9.8) | 1.3% | — | Nexusphp Project Nexusphp | 17/8/2017 | 17/6/2026 | SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the conusr parameter. | |
| Modificada | Media (6.1) | 0.67% | — | Nexusphp Project Nexusphp | 17/8/2017 | 17/6/2026 | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php. | |
| Modificada | Media (6.1) | 0.67% | — | Nexusphp Project Nexusphp | 10/8/2017 | 17/6/2026 | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php. | |
| Modificada | Media (6.1) | 0.64% | — | Nexusphp Project Nexusphp | 9/8/2017 | 17/6/2026 | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php. | |
| Modificada | Media (6.1) | 0.67% | — | Nexusphp Project Nexusphp | 7/8/2017 | 17/6/2026 | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action. | |
| Modificada | Media (4.2) | 1.7% | — | Cisco Nx-osCisco Nx-os FOR Nexus 5500 Platform SwitchesCisco Nx-os FOR Nexus 5600 Platform SwitchesCisco Nx-os FOR Nexus 7700 Series Switches+3 | 7/8/2017 | 17/6/2026 | Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an… | |
| Modificada | Media (6.1) | 0.67% | — | Nexusphp | 26/7/2017 | 17/6/2026 | NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag. | |
| Modificada | Alta (7.8) | 1.6% | — | Mh-nexus HEX Editor | 5/7/2017 | 17/6/2026 | Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a "Data from Faulting Address controls Code Flow" issue. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined… | |
| Modificada | Media (6.5) | 0.68% | — | Cisco MDS 9000 Nx-osCisco Nx-os FOR Nexus 5500 Platform SwitchesCisco Nx-os FOR Nexus 5600 Platform SwitchesCisco Nx-os FOR Nexus 7700 Series Switches+1 | 13/6/2017 | 17/6/2026 | A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when an FCoE-related process unexpectedly reloads. This vulnerability affects Cisco NX-OS Software on the following… | |
| Modificada | Media (6.5) | 1.0% | — | Cisco Nexus 1000v Intercloud Firmware | 14/12/2016 | 17/6/2026 | A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. Known Affected Releases: 2.2(1). | |
| Modificada | Alta (8.6) | 1.4% | — | American Auto-matrix Aspect-matrix Building Automation Front-end Solutions ApplicationAmerican Auto-matrix Aspect-nexus Building Automation Front-end Solutions Application | 5/10/2016 | 17/6/2026 | American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application store passwords in cleartext, which allows remote attackers to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.5) | 1.5% | — | American Auto-matrix Aspect-matrix Building Automation Front-end Solutions ApplicationAmerican Auto-matrix Aspect-nexus Building Automation Front-end Solutions Application | 5/10/2016 | 17/6/2026 | American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application allow remote attackers to read arbitrary files via unspecified vectors, as demonstrated by the configuration file. | |
| Modificada | Alta (7.8) | 0.21% | — | Linux KernelGoogle Nexus 5X FirmwareGoogle Nexus 6P Firmware | 5/5/2016 | 17/6/2026 | The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorrect integer data type, which allows attackers to cause a denial of… | |
| Modificada | Media (5) | 3.0% | — | Cisco Nx-osCisco Nexus 1000vCisco MDS 9000 Nx-os | 12/6/2015 | 17/6/2026 | The banner (aka MOTD) implementation in Cisco NX-OS 4.1(2)E1(1f) on Nexus 4000 devices, 5.2(1)SV3(2.1) on Nexus 1000V devices, 6.0(2)N2(2) on Nexus 5000 devices, 6.2(11) on MDS 9000 devices, 6.2(12) on Nexus 7000 devices, 7.0(3) on Nexus 9000 devices, and 7.2(0)ZN(99.67) on Nexus 3000 devices allows remote attackers… | |
| Modificada | Alta (7.5) | 1.9% | — | Sonatype Nexus | 5/1/2015 | 17/6/2026 | Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Nexus 1000v Intercloud | 20/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the vCloud Director component in Cisco Nexus 1000V InterCloud for VMware allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuq90524. | |
| Modificada | Media (5) | 4.7% | 💥 PoC | Cisco Nx-osCisco Nexus 5000Cisco Nexus 5010Cisco Nexus 5010p Switch+11 | 19/8/2014 | 17/6/2026 | The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616. | |
| Modificada | Media (5) | 2.1% | — | Cisco Nx-osCisco Nexus 9000 | 11/8/2014 | 17/6/2026 | Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, aka Bug ID CSCuo02489. |