Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.1% | — | Apache Mina | 1/10/2019 | 17/6/2026 | Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache… | |
| Modificada | Alta (7.8) | 0.94% | — | Soumu Electronic Reception AND Examination OF Application FOR Radio Licenses | 17/5/2019 | 17/6/2026 | Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.94% | — | Soumu Electronic Reception AND Examination OF Application FOR Radio Licenses | 17/5/2019 | 17/6/2026 | Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (6.5) | 1.6% | — | Incsub Forminator | 4/3/2019 | 17/6/2026 | The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission. | |
| Modificada | Media (6.1) | 1.3% | — | Incsub Forminator | 4/3/2019 | 17/6/2026 | The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll. | |
| Modificada | Media (5.9) | 58% | 💥 Exploit | Openbsd OpensshWinscpCanonical Ubuntu LinuxDebian Linux+15 | 31/1/2019 | 17/6/2026 | An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp… | |
| Modificada | Media (5.4) | 1.5% | — | Learning AND Examination Management System Script Project Learning AND Examination Management System Script | 23/2/2018 | 17/6/2026 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Learning and Examination Management System Script 2.3.1 via a crafted message. | |
| Modificada | Alta (8.8) | 1.2% | — | Reddit Terminal Viewer Project Reddit Terminal Viewer | 14/12/2017 | 17/6/2026 | scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. | |
| Modificada | Media (6.1) | 1.1% | — | Geminabox Project Geminabox | 13/11/2017 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. | |
| Modificada | Alta (8.8) | 0.50% | — | Geminabox Project Geminabox | 25/9/2017 | 17/6/2026 | geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. | |
| Modificada | Media (5.4) | 0.68% | — | Geminabox Project Geminabox | 25/9/2017 | 17/6/2026 | geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. | |
| Modificada | Alta (7.8) | 0.32% | — | Lxterminal Project Lxterminal | 8/5/2017 | 17/6/2026 | unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control). | |
| Modificada | Media (5.3) | 0.98% | — | Paloaltonetworks Terminal Services Agent | 20/3/2017 | 17/6/2026 | Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors. | |
| Modificada | Alta (7.8) | 0.98% | 💥 Exploit | Paloaltonetworks Terminal Services Agent | 27/1/2017 | 17/6/2026 | Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation. | |
| Modificada | Alta (7.5) | 0.91% | — | Paloaltonetworks Terminal Services Agent | 27/1/2017 | 17/6/2026 | Palo Alto Networks Terminal Services Agent before 7.0.7 allows attackers to spoof arbitrary users via unspecified vectors. | |
| Modificada | Media (4) | 1.6% | — | Innominate Mguard Firmware | 30/8/2015 | 17/6/2026 | The IPsec SA establishment process on Innominate mGuard devices with firmware 8.x before 8.1.7 allows remote authenticated users to cause a denial of service (VPN service restart) by leveraging a peer relationship to send a crafted configuration with compression. | |
| Modificada | Alta (10) | 4.7% | — | Wavelink Terminal Emulation | 29/5/2015 | 17/6/2026 | Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote attackers to execute arbitrary code via a large HTTP header. | |
| Modificada | Alta (9) | 3.1% | — | Innominate Mguard Firmware | 20/12/2014 | 17/6/2026 | Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting. | |
| Modificada | Alta (10) | 6.0% | — | Emerson DL 8000 Remote Terminal Unit FirmwareEmerson DL 8000 Remote Terminal UnitEmerson ROC 800l Remote Terminal Unit FirmwareEmerson ROC 800l Remote Terminal Unit+2 | 8/12/2014 | 16/6/2026 | Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a TCP replay attack. | |
| Modificada | Alta (7.5) | 9.1% | 💥 Exploit | Digitalvidhya Digi Online Examination System | 20/11/2014 | 17/6/2026 | Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/uploads/images/. | |
| Modificada | Media (5.4) | 0.27% | — | Elsio Mapa DA Mina | 19/10/2014 | 17/6/2026 | The MAPA DA MINA (aka com.wMAPADAMINA) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.1) | 2.0% | — | Cobham Ailor 6110 Mini-c GmdssCobham Sailor 6006 Message TerminalCobham Sailor 6222 VHFCobham Sailor 6300 MF / HF | 15/8/2014 | 17/6/2026 | Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 command. NOTE: the vendor reportedly states "there is no possibility to exploit another user's credentials. | |
| Modificada | Alta (9.3) | 2.8% | — | Cobham Ailor 6110 Mini-c GmdssCobham Sailor 6006 Message TerminalCobham Sailor 6222 VHFCobham Sailor 6300 MF / HF | 15/8/2014 | 17/6/2026 | The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send an SNMP request and a TFTP response. | |
| Modificada | Media (5) | 3.4% | — | Innominate Mguard Firmware | 30/7/2014 | 17/6/2026 | Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request. | |
| Modificada | Baja (3.5) | 1.4% | — | Omron NS Series System Program FirmwareOmron Ns10 HMI TerminalOmron Ns12 HMI TerminalOmron Ns15 HMI Terminal+2 | 24/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data. |