Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 73% | 💥 Exploit | Titanhq Spamtitan | 17/9/2020 | 17/6/2026 | An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server. | |
| Modificada | Alta (7.8) | 0.50% | — | Opensuse LeapOpensuse Tumbleweed Kopano-spamd | 29/6/2020 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE… | |
| Modificada | Alta (7.5) | 1.7% | — | PAM Tacplus Project PAM TacplusDebian LinuxCanonical Ubuntu LinuxArista Cloudvision Portal | 6/6/2020 | 17/6/2026 | In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. | |
| Modificada | Media (4.8) | 0.61% | — | Phpipam | 20/5/2020 | 17/6/2026 | phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget. | |
| Modificada | Crítica (9.8) | 4.8% | — | Pam-krb5 Project Pam-krb5Debian Linux | 31/3/2020 | 17/6/2026 | pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underlying Kerberos library by a single '\0' byte if an attacker responds to a prompt with an answer of a carefully chosen… | |
| Modificada | Alta (8.8) | 0.73% | — | Phpipam | 4/3/2020 | 17/6/2026 | An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens. | |
| Modificada | Alta (7.5) | 3.5% | — | Freeradius PAM RadiusDebian LinuxCanonical Ubuntu Linux | 24/2/2020 | 17/6/2026 | add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might… | |
| Modificada | Alta (8.1) | 6.5% | — | Apache Spamassassin | 30/1/2020 | 17/6/2026 | A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. This issue is less stealthy and attempts to exploit the issue will throw warnings. Thanks to Damian Lukowski at credativ… | |
| Modificada | Alta (8.1) | 7.1% | — | Apache Spamassassin | 30/1/2020 | 17/6/2026 | A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. With this bug unpatched, exploits can be injected in a number of scenarios including the same privileges as spamd is… | |
| Modificada | Alta (7.5) | 0.94% | — | Spamdyke | 15/1/2020 | 16/6/2026 | spamdyke prior to 4.2.1: STARTTLS reveals plaintext | |
| Modificada | Alta (7.5) | 7.2% | — | Apache SpamassassinDebian Linux | 12/12/2019 | 17/6/2026 | In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly. | |
| Modificada | Media (6.7) | 0.87% | — | Apache SpamassassinDebian Linux | 12/12/2019 | 17/6/2026 | In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted… | |
| Modificada | Crítica (9.8) | 2.0% | — | Yubico PAM ModuleDebian Linux | 26/11/2019 | 16/6/2026 | Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question… | |
| Modificada | Alta (7.5) | 1.3% | — | PAM Shield Project PAM ShieldDebian Linux | 21/11/2019 | 16/6/2026 | pam_shield before 0.9.4: Default configuration does not perform protective action | |
| Modificada | Media (6.1) | 1.3% | — | Cleantalk Spam Protection, Antispam, Firewall | 13/11/2019 | 17/6/2026 | The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack… | |
| Modificada | Alta (7.8) | 0.36% | — | Pam-python Project Pam-pythonDebian LinuxCanonical Ubuntu Linux | 24/9/2019 | 17/6/2026 | pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups. | |
| Modificada | Crítica (9.8) | 1.9% | — | Phpipam | 22/9/2019 | 17/6/2026 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used. | |
| Modificada | Crítica (9.8) | 1.9% | — | Phpipam | 22/9/2019 | 17/6/2026 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used. | |
| Modificada | Crítica (9.8) | 1.9% | — | Phpipam | 22/9/2019 | 17/6/2026 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used. | |
| Modificada | Crítica (9.8) | 4.3% | 💥 Exploit | Phpipam | 22/9/2019 | 17/6/2026 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Phpipam | 22/9/2019 | 17/6/2026 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used. | |
| Modificada | Media (6.1) | 1.4% | — | Wpcerber Cerber Security Antispam & Malware Scan | 17/9/2019 | 17/6/2026 | The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header. | |
| Modificada | Alta (7.5) | 1.3% | — | Titanhq Spamtitan | 5/6/2019 | 17/6/2026 | In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands. | |
| Modificada | Alta (8.1) | 2.1% | — | Yubico Pam-u2f | 4/6/2019 | 17/6/2026 | In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak… | |
| Modificada | Alta (7.5) | 2.9% | — | Yubico Pam-u2f | 4/6/2019 | 17/6/2026 | Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part… |