Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.9% | — | Cisco IOSCisco Aironet 1040Cisco Aironet 1140Cisco Aironet 1260+15 | 6/8/2012 | 16/6/2026 | Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426. | |
| Modificada | Alta (9.3) | 28% | 💥 Exploit | EMC Captiva Quickscan PROEMC Documentum Applicationxtender DesktopIntelligent Platforms Proficy Batch ExecutionIntelligent Platforms Proficy Historian+3 | 5/7/2012 | 16/6/2026 | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5;… | |
| Modificada | Media (4.3) | 1.0% | — | Jxtended Comments | 9/12/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the JXtended Comments component before 1.3.1 for Joomla allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Adobe Extendedscript Toolkit CS5 | 27/8/2010 | 16/6/2026 | Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jsx file. | |
| Modificada | Alta (10) | 13% | — | EMC Documentum Applicationxtender Workflow Manager | 22/10/2009 | 16/6/2026 | Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to upload arbitrary files, and execute arbitrary code, via directory traversal sequences in requests to TCP port 2606. | |
| Modificada | Alta (10) | 5.6% | — | EMC Documentum Applicationxtender | 22/10/2009 | 16/6/2026 | Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to execute arbitrary code via crafted packet data to TCP port 2606. | |
| Modificada | Alta (10) | 5.6% | — | Claudio Matsuoka Extended Module Player | 13/9/2009 | 16/6/2026 | Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Claudio Matsuoka Extended Module Player | 13/9/2009 | 16/6/2026 | Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow. | |
| Modificada | Alta (9) | 4.1% | — | EMC Diskxtender | 14/4/2008 | 16/6/2026 | Stack-based buffer overflow in the File System Manager for EMC DiskXtender 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted request to the RPC interface. | |
| Modificada | Alta (9) | 3.3% | — | EMC Diskxtender | 14/4/2008 | 16/6/2026 | Format string vulnerability in EMC DiskXtender MediaStor 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted message to the RPC interface. | |
| Modificada | Crítica (9.8) | 4.9% | — | EMC Diskxtender | 14/4/2008 | 16/6/2026 | EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface. | |
| Modificada | Alta (7.8) | 2.4% | — | SUN Extended System Control Facility XCP 1040 | 15/12/2007 | 16/6/2026 | Unspecified vulnerability in the Sun eXtended System Control Facility (XSCF) Control Package (XCP) firmware before 1050 on SPARC Enterprise M4000, M5000, M8000, and M9000 servers allows remote attackers to cause a denial of service (reboot) via (1) telnet, (2) ssh, or (3) http network traffic that triggers memory… | |
| Modificada | Alta (9.3) | 6.0% | — | Novell Extend Director | 18/6/2007 | 16/6/2026 | The launch method in the LocalExec ActiveX control (LocalExec.ocx) in Novell exteNd Director 4.1 and Portal Services allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (5) | 1.4% | — | Hitachi TP1 NET Osi-tp-extended | 5/6/2007 | 16/6/2026 | Unspecified vulnerability in Hitachi TP1/NET/OSI-TP-Extended on HI-UX/WE2 before 20070213, and on HP-UX before 20070314, allows remote attackers to cause a denial of service via certain data to a port. | |
| Modificada | Alta (7.5) | 1.3% | — | Drupal Extended Tracker | 30/10/2006 | 16/6/2026 | SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before 1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "parameters from URLs." | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Mamboxchange Extended Registration | 12/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), aka regdetailed, 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Extended Interior Gateway Routing Protocol | 21/12/2005 | 16/6/2026 | MD5 Neighbor Authentication in Extended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS 11.3 and later, does not include the Message Authentication Code (MAC) in the checksum, which allows remote attackers to sniff message hashes and (1) replay EIGRP HELLO messages or (2) cause a denial of… | |
| Modificada | Baja (3.6) | 0.48% | — | IBM Informix Dynamic ServerIBM Informix Extended Parallel Server | 31/12/2004 | 16/6/2026 | IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log file to onedcu or (2) read arbitrary files via a symlink attack on a file in /tmp to onshowaudit. | |
| Modificada | Media (4.6) | 0.47% | — | IBM Informix Dynamic ServerIBM Informix Extended Parallel Server | 31/12/2004 | 16/6/2026 | Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable. | |
| Modificada | Alta (7.2) | 1.4% | 💥 Exploit | IBM Informix Dynamic ServerIBM Informix Extended Parallel Server | 27/1/2004 | 16/6/2026 | Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable. | |
| Modificada | Alta (7.8) | 4.3% | — | Extended Interior Gateway Routing ProtocolCisco IOS | 31/12/2002 | 16/6/2026 | Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 and other products, allows remote attackers to cause a denial of service (flood) by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network. |