Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Labanquepostale Acces Compte | 9/9/2014 | 17/6/2026 | The Acces Compte (aka com.fullsix.android.labanquepostale.accountaccess) application 3.2.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 3.1% | — | SAP Crystal Reports | 4/9/2014 | 17/6/2026 | Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT file. | |
| Modificada | Media (6.8) | 3.8% | — | SAP Crystal Reports | 4/9/2014 | 17/6/2026 | Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data source string in an RPT file. | |
| Modificada | Media (4.3) | 1.00% | — | Labanquepostale | 2/9/2014 | 17/6/2026 | The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework. | |
| Modificada | Media (6.3) | 1.9% | — | Cisco Transport Gateway Installation Software | 29/8/2014 | 17/6/2026 | The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) does not validate an unspecified parameter, which allows remote authenticated users to cause a denial of service (service crash) via a crafted string, aka Bug ID CSCuq31819. | |
| Modificada | Media (5) | 2.2% | — | Cisco Transport Gateway Installation Software | 28/8/2014 | 17/6/2026 | The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted URL, aka Bug ID CSCuq31503. | |
| Modificada | Media (4.3) | 2.0% | — | Cisco Transport Gateway Installation Software | 28/8/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuq31129, CSCuq31134, CSCuq31137,… | |
| Modificada | Baja (2.1) | 0.46% | — | Katello Installer | 14/5/2014 | 16/6/2026 | Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Vastal Phpvid | 19/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to browse_videos.php or the (2) cat parameter to groups.php. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Vastal Phpvid | 19/8/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n" parameter to (1) browse_videos.php or (2) members.php. NOTE: the cat parameter is already covered by CVE-2008-4157. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Vastal Freelance Zone | 31/1/2013 | 16/6/2026 | SQL injection vulnerability in show_code.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the code_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal Agent Zone | 2/2/2012 | 16/6/2026 | SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from parameter. | |
| Modificada | Baja (2.1) | 0.30% | — | Flexerasoftware Installshield | 19/1/2012 | 16/6/2026 | Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between… | |
| Modificada | Media (4.3) | 1.1% | — | SAP Crystal Reports Server | 14/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pubDBLogon.jsp in SAP Crystal Report Server 2008 allows remote attackers to inject arbitrary web script or HTML via the service parameter. | |
| Modificada | Alta (9.3) | 7.6% | — | Rockwellautomation RslinxRockwellautomation EDS Hardware Installation Tool | 22/6/2011 | 16/6/2026 | Buffer overflow in RSEds.dll in RSHWare.exe in the EDS Hardware Installation Tool 1.0.5.1 and earlier in Rockwell Automation RSLinx Classic before 2.58 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed .eds file. | |
| Modificada | Media (4.3) | 1.3% | — | Apple InstallerApple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server. | |
| Modificada | Alta (9.3) | 47% | 💥 Exploit | SAP Crystal Reports | 22/12/2010 | 16/6/2026 | Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion property value. | |
| Modificada | Alta (9.3) | 4.8% | — | Sonicwall Ssl-vpn End-point Interrogator/installer Activex Control | 3/11/2010 | 16/6/2026 | Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method. | |
| Modificada | Alta (10) | 6.4% | — | SAP Crystal Reports | 17/8/2010 | 16/6/2026 | Integer overflow in the OBGIOPServerWorker::extractHeader function in the ebus-3-3-2-6.dll module in SAP Crystal Reports 2008 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GIOP packet with a crafted size, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 0.94% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968. | |
| Modificada | Media (4.6) | 0.47% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data, and consequently gain privileges, via unknown vectors. | |
| Modificada | Media (6.8) | 0.94% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1971. | |
| Modificada | Baja (3.6) | 0.47% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data via unknown vectors. | |
| Modificada | Alta (9.3) | 4.9% | — | Epicgames Unreal EngineEpicgames Postal 2Epicgames Raven ShieldEpicgames Swat 4+2 | 12/7/2010 | 16/6/2026 | Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL… | |
| Modificada | Alta (7.5) | 2.5% | — | Wildbit Beanstalkd | 8/6/2010 | 16/6/2026 | The put command functionality in beanstalkd 1.4.5 and earlier allows remote attackers to execute arbitrary Beanstalk commands via the body in a job that is too big, which is not properly handled by the dispatch_cmd function in prot.c. |