Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

366 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (1.9)0.47%—Linux KernelDebian LinuxOpensuseSuse Linux Enterprise Desktop+38/9/201016/6/2026
The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a…
ModificadaAlta (7.8)0.41%—Linux KernelVmware ESXCanonical Ubuntu LinuxDebian Linux+118/9/201016/6/2026
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by…
ModificadaAlta (10)2.9%—Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+18/9/201016/6/2026
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via…
ModificadaMedia (5.5)0.38%—Linux KernelVmware ESXCanonical Ubuntu LinuxSuse Linux Enterprise High Availability Extension+28/9/201016/6/2026
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
ModificadaAlta (7)0.66%💥 ExploitLinux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+27/5/201016/6/2026
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that…
ModificadaAlta (10)17%—CA Xosoft Content DistributionCA Xosoft High AvailabilityXosoft Replication7/4/201016/6/2026
Multiple buffer overflows in CA XOsoft r12.0 and r12.5 allow remote attackers to execute arbitrary code via (1) a malformed request to the ws_man/xosoapapi.asmx SOAP endpoint or (2) a long string to the entry_point.aspx service.
ModificadaMedia (5)2.1%—CA Xosoft Content DistributionCA Xosoft High AvailabilityXosoft Replication7/4/201016/6/2026
CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP request.
ModificadaMedia (5)2.1%—CA Xosoft Content DistributionCA Xosoft High AvailabilityXosoft Replication7/4/201016/6/2026
CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.
ModificadaAlta (10)11%—Symantec Backup Exec Continuous Protection ServerSymantec Veritas Application DirectorSymantec Veritas Backup ExecSymantec Veritas Cluster Server+1911/12/200916/6/2026
VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA)…
ModificadaMedia (5)2.2%—Code-crafters Ability Mail Server28/9/200916/6/2026
Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command.
ModificadaBaja (2.1)0.25%—SUN Lightweight Availability Collection Tool5/7/200916/6/2026
Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to overwrite arbitrary files via unspecified vectors.
ModificadaMedia (4)1.4%—Code-crafters Ability Mail Server23/11/200716/6/2026
Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and possibly (2) a blank string in unspecified messages.
ModificadaAlta (7.8)2.1%💥 ExploitNessus Vulnerability Scanner30/7/200716/6/2026
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability.
ModificadaAlta (9.3)11%💥 ExploitNessus Vulnerability Scanner30/7/200716/6/2026
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the saveNessusRC method, which writes text specified by the addsetConfig method, possibly related to the…
ModificadaAlta (7.8)5.7%💥 ExploitNessus Vulnerability Scanner27/7/200716/6/2026
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll.
ModificadaMedia (4.3)1.9%—Hitachi Jp1-hicommand Device ManagerHitachi Jp1-hicommand Global Link Availability ManagerHitachi Jp1-hicommand Replication MonitorHitachi Jp1-hicommand Tiered Storage Manager9/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in the Hitachi JP1/HiCommand Device Manager, Tiered Storage Manager, Replication Monitor, and GlobalLink Availability Manager before 20070528 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.
ModificadaMedia (5)1.3%—Hitachi Jp1-hicommand Device ManagerHitachi Jp1-hicommand Global Link Availability ManagerHitachi Jp1-hicommand Replication MonitorHitachi Jp1-hicommand Tiered Storage Manager+13/4/200716/6/2026
Unspecified vulnerability in Hitachi JP1/HiCommand DeviceManager, Global Link Availability Manager, Replication Monitor, Tiered Storage Manager, and Tuning Manager allows local users to obtain authentication information via unspecified vectors.
ModificadaBaja (1.9)1.8%💥 ExploitAcunetix WEB Vulnerability Scanner9/1/200716/6/2026
Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-Length values.
ModificadaMedia (5)14%💥 ExploitHigh Availability Linux Project Heartbeat17/8/200616/6/2026
The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial of service (crash) via the length parameter in a heartbeat message.
ModificadaMedia (5)2.4%—Secure Elements Class 5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER messages, which leads to a buffer overflow (probably an over-read).
ModificadaMedia (5)2.2%—Secure Elements C5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large number of forged client registration messages.
ModificadaMedia (5)2.1%—Secure Elements C5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read sensitive vulnerability information.
ModificadaMedia (5)1.9%—Secure Elements C5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEID of a protected asset, which can be used in other attacks against AVR.
ModificadaAlta (7.5)2.2%—Secure Elements C5 Enterprise Vulnerability Management31/5/200616/6/2026
The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attackers to gain access to servers via the console.
ModificadaMedia (5)1.9%—Secure Elements Class 5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages.
Orbitaley — Vulnerabilidades