Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

366 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)63%💥 ExploitLighttpdDebian LinuxOpensuseSuse Linux Enterprise High Availability Extension+114/3/201417/6/2026
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
ModificadaMedia (4.3)1.8%💥 ExploitMcafee Vulnerability Manager28/1/201416/6/2026
Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HTML via the cert_cn cookie parameter.
ModificadaMedia (6.8)0.69%—Mcafee Vulnerability Manager16/1/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to hijack the authentication of users for requests that modify HTML via unspecified vectors related to the "response web page."
ModificadaMedia (4.3)2.0%—Mcafee Vulnerability Manager16/1/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.4%💥 ExploitCode-crafters Ability Mail Server21/12/201317/6/2026
Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.
ModificadaAlta (7.2)0.98%💥 ExploitLinux KernelRedhat Enterprise LinuxRedhat Enterprise MRGSuse Linux Enterprise Desktop+229/4/201316/6/2026
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then…
ModificadaMedia (4.3)0.94%—EMC Smarts IP ManagerEMC Smarts Mpls ManagerEMC Smarts Network Protocol ManagerEMC Smarts Server Manager+228/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in EMC Smarts IP Manager, Smarts Service Assurance Manager, Smarts Server Manager, Smarts VoIP Availability Manager, Smarts Network Protocol Manager, and Smarts MPLS Manager before 9.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaAlta (7.5)41%💥 ExploitCrawlability Vbseo1/10/201216/6/2026
The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace…
ModificadaMedia (4.6)1.1%—HP Business Availability Center8/9/201216/6/2026
HP Business Availability Center (BAC) 8.07 allows remote authenticated users to hijack web sessions via unspecified vectors.
ModificadaMedia (6.8)0.97%—HP Business Availability Center8/9/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (4.3)1.6%—HP Business Availability Center8/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.5)0.52%—Linux KernelFedoraproject FedoraSuse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+117/5/201216/6/2026
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact…
ModificadaAlta (7.8)0.35%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRGSuse Linux Enterprise Desktop+217/5/201216/6/2026
The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace…
ModificadaMedia (5.5)0.40%—Linux KernelRedhat Enterprise MRGSuse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+117/5/201216/6/2026
The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.
ModificadaMedia (5.5)0.47%—Linux KernelCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+217/5/201216/6/2026
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
ModificadaMedia (4.3)1.9%—HP Business Availability Center5/4/201216/6/2026
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 9.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.7%—HP Business Availability Center16/5/201116/6/2026
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.06 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)2.1%—HP Business Availability CenterHP Business Service Management24/1/201116/6/2026
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.2)0.56%—Linux KernelOpensuseSuse Linux Enterprise High Availability ExtensionSuse Linux Enterprise Real Time11/1/201116/6/2026
Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request, which triggers a buffer overflow.
ModificadaAlta (7.5)5.3%—Arcserve Replication AND High AvailabilityCA Xosoft Content DistributionCA Xosoft High AvailabilityXosoft Replication7/1/201116/6/2026
Buffer overflow in mng_core_com.dll in CA XOsoft Replication r12.0 SP1 and r12.5 SP2 rollup, CA XOsoft High Availability r12.0 SP1 and r12.5 SP2 rollup, CA XOsoft Content Distribution r12.0 SP1 and r12.5 SP2 rollup, and CA ARCserve Replication and High Availability (RHA) r15.0 SP1 allows remote attackers to execute…
ModificadaBaja (2.1)0.46%—Linux KernelRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationSuse Linux Enterprise Desktop+223/12/201016/6/2026
arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.
ModificadaMedia (5.5)0.39%—Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+130/9/201016/6/2026
kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and outage of all function tracing files) via an lseek call on a file…
ModificadaMedia (5.5)0.38%—Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+130/9/201016/6/2026
Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
ModificadaAlta (7.1)0.39%—Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise High Availability ExtensionSuse Linux Enterprise Desktop+130/9/201016/6/2026
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.
ModificadaAlta (7.2)3.7%💥 ExploitLinux KernelFedoraproject FedoraDebian LinuxOpensuse+48/9/201016/6/2026
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a denial of service (system crash) via crafted CAN traffic.
Orbitaley — Vulnerabilidades