Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 22% | 💥 Exploit | Schneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+9 | 1/4/2014 | 16/6/2026 | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header. | |
| Modificada | Alta (7.8) | 2.1% | — | HP Storeonce 2610 Iscsi Backup SystemHP Storeonce 2620 Iscsi Backup SystemHP Storeonce 4210 FC Backup SystemHP Storeonce 4210 Iscsi Backup System+4 | 29/3/2014 | 17/6/2026 | Unspecified vulnerability in HP StoreOnce Virtual Storage Appliance (VSA) before 3.7.2, StoreOnce 26xx and 4210 iSCSI Backup System before 3.9.0, StoreOnce 4210 FC Backup System before 3.9.0, and StoreOnce 4xxx Backup System before 3.9.0 allows remote attackers to obtain sensitive information or cause a denial of… | |
| Modificada | Media (6.8) | 11% | 💥 Exploit | Conceptronic Cipcamptiwl 1.0 FirmwareConceptronic Cipcamptiwl | 17/1/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. | |
| Modificada | Alta (7.8) | 1.5% | — | Conceptronic C54apm FirmwareConceptronic C54apm | 10/1/2014 | 17/6/2026 | The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via an HTTP request, as demonstrated by stored XSS attacks. | |
| Modificada | Media (4.3) | 1.2% | — | Conceptronic C54apm FirmwareConceptronic C54apm | 10/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to inject arbitrary web script or HTML via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to goform/formWlanSetup. | |
| Modificada | Media (4.3) | 0.98% | — | Conceptronic C54apm FirmwareConceptronic C54apm | 10/1/2014 | 17/6/2026 | CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the submit-url parameter in a Refresh action. | |
| Modificada | Media (5.8) | 1.2% | — | Conceptronic C54apm FirmwareConceptronic C54apm | 10/1/2014 | 17/6/2026 | Multiple open redirect vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to… | |
| Modificada | Media (4.7) | 0.30% | — | Cooperindustries SMP 16 Gateway (data Concentrator)Cooperindustries SMP 4/dp Gateway (data Concentrator)Cooperindustries SMP 4 Gateway (data Concentrator) | 17/12/2013 | 16/6/2026 | The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line. | |
| Modificada | Alta (7.1) | 1.3% | — | Cooperindustries SMP 16 Gateway (data Concentrator)Cooperindustries SMP 4/dp Gateway (data Concentrator)Cooperindustries SMP 4 Gateway (data Concentrator) | 17/12/2013 | 16/6/2026 | The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows remote attackers to cause a denial of service (reboot or link outage) via a crafted DNP3 TCP packet. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Team Concert | 10/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary… | |
| Modificada | Alta (7.8) | 2.5% | — | HP Storeonce D2D | 28/8/2013 | 16/6/2026 | Unspecified vulnerability in HP StoreOnce D2D Backup System 1.x before 1.2.19 and 2.x before 2.3.0 allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Alta (7.1) | 1.4% | — | Moxa Oncell Gateway FirmwareMoxa Oncell Gateway G3111Moxa Oncell Gateway G3151Moxa Oncell Gateway G3211+1 | 9/8/2013 | 16/6/2026 | Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, which makes it easier for remote attackers to obtain access by leveraging knowledge of a key from a product installation elsewhere. | |
| Modificada | Alta (7.7) | 0.82% | — | HP Storeonce D2D | 30/6/2013 | 16/6/2026 | The HP StoreOnce D2D backup system with software before 3.0.0 has a default password of badg3r5 for the HPSupport account, which allows remote attackers to obtain administrative access and delete data via an SSH session. | |
| Modificada | Media (5.8) | 0.57% | — | Harald Ponce DE Leon Authorize.netOscommerce | 4/11/2012 | 16/6/2026 | The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (6.8) | 0.64% | — | IBM Rational Team Concert | 1/10/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items. | |
| Modificada | Media (5) | 1.4% | — | Conceptcms | 23/9/2011 | 16/6/2026 | conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by sys_libs/umlib/um_authserver.inc.php and certain other files. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Rational Team Concert | 30/6/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165513. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Rational Team Concert | 30/6/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165511. | |
| Modificada | Baja (3.5) | 0.89% | — | IBM Rational Team Concert | 14/2/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report. | |
| Modificada | Media (5) | 1.6% | — | Cisco ASA 5500Cisco PIX 500Cisco VPN 3000 ConcentratorCisco VPN 3005 Concentrator+5 | 30/11/2010 | 16/6/2026 | The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote… | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Runcms Myannonces | 24/7/2009 | 16/6/2026 | SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Cms.brdconcept Cms-brd | 24/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the menuclick parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Runcms Myannonces | 21/2/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Divideconcept VHD WEB Pack | 6/2/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |
| Modificada | Media (6.8) | 3.5% | 💥 Exploit | CJG Explorer PROVincent Blavet Phpconcept Library | 14/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, as used in CJG EXPLORER PRO 3.3 and earlier and probably other products, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter. NOTE: CVE disputes this… |