Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.73% | — | Nttdocomo Overseas Usage | 9/8/2013 | 16/6/2026 | The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.11 network's coverage area. | |
| Modificada | Media (4.3) | 2.0% | — | IBM Websphere Application ServerIBM Websphere Message Broker | 29/5/2013 | 16/6/2026 | IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a… | |
| Modificada | Alta (10) | 46% | 💥 Exploit | Bigantsoft Bigant IM Message Server | 24/2/2013 | 16/6/2026 | Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request. | |
| Modificada | Media (5) | 47% | 💥 Exploit | Bigantsoft Bigant IM Message Server | 24/2/2013 | 16/6/2026 | BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Bigantsoft Bigant IM Message Server | 24/2/2013 | 16/6/2026 | SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request. | |
| Modificada | Baja (2.6) | 1.1% | — | IBM Websphere Message Broker | 20/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Websphere Message Broker | 20/2/2013 | 16/6/2026 | IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (infinite loop) via a crafted query string. | |
| Modificada | Media (5) | 1.4% | — | IBM Websphere Message Broker | 20/2/2013 | 16/6/2026 | IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors. | |
| Modificada | Media (6.9) | 0.37% | — | IBM Websphere Message Broker | 5/12/2012 | 16/6/2026 | IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300. | |
| Modificada | Media (5.8) | 0.57% | — | OscommerceSagepay Sage PAY Direct Module | 4/11/2012 | 16/6/2026 | The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Sagem F@st 2604 FirmwareSagem F@st 2604 | 8/10/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in password.cgi in Sagem F@ST 2604 253180972B allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter. | |
| Modificada | Media (6.8) | 0.86% | — | Symantec Message Filter | 5/7/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute application commands or (2) create admin accounts. | |
| Modificada | Media (4.3) | 1.5% | — | Symantec Message Filter | 5/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.77% | — | Symantec Message Filter | 5/7/2012 | 16/6/2026 | Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Baja (3.3) | 0.81% | — | Symantec Message Filter | 5/7/2012 | 16/6/2026 | Brightmail Control Center in Symantec Message Filter 6.3 does not properly restrict establishment of sessions to the listening port, which allows remote attackers to obtain potentially sensitive version information via unspecified vectors. | |
| Modificada | Alta (10) | 2.2% | — | Zhou BO Message Forwarder | 15/3/2012 | 16/6/2026 | Unspecified vulnerability in the Message Forwarder (com.gmail.zbnetium) application 1.12.20110409.1 for Android has unknown impact and attack vectors. | |
| Modificada | Alta (10) | 1.4% | — | Goforandroid GO Message Widget | 7/3/2012 | 16/6/2026 | Unspecified vulnerability in the GO Message Widget (com.gau.go.launcherex.gowidget.smswidget) application 1.9, 2.1, and 2.3 for Android has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 0.84% | — | Sage-mozdev Sage | 8/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Sage add-on 1.3.10 and earlier for Firefox allows remote attackers to inject arbitrary web script or HTML via a crafted feed, a different vulnerability than CVE-2009-4102. | |
| Modificada | Alta (7.2) | 0.38% | — | Tibco RendezvousTibco Enterprise Message ServiceTibco Runtime AgentTibco Silver BPM Service+2 | 4/2/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver BusinessWorks Service 1.0.0, when running on Unix systems, allow… | |
| Modificada | Media (5.7) | 0.34% | — | Oracle Glassfish ServerOracle Java System Message Queue | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in Oracle GlassFish 2.1, 2.1.1, and 3.0.1, and Java System Message Queue 4.1 allows local users to affect confidentiality, integrity, and availability, related to Java Message Service (JMS). | |
| Modificada | Alta (9.3) | 3.4% | — | Sage.mozdev SageMozilla Firefox | 29/11/2009 | 16/6/2026 | Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed. | |
| Modificada | Media (5) | 2.6% | — | Sophos Puremessage FOR Microsoft Exchange | 27/8/2009 | 16/6/2026 | The installation of Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2, when both anti-virus and anti-spam are supported, does not create or launch the associated scan engines when the system is under heavy load, which has unspecified impact, probably remote bypass of scanner protection or a denial of service… | |
| Modificada | Media (5) | 3.3% | — | Sophos Puremessage FOR Microsoft Exchange | 27/8/2009 | 16/6/2026 | Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (EdgeTransport.exe termination) via a TNEF-encoded message with a crafted rich text body that is not properly handled during conversion to plain text. NOTE: this might be related to CVE-2008-7104. | |
| Modificada | Media (5) | 3.3% | — | Sophos Puremessage FOR Microsoft Exchange | 27/8/2009 | 16/6/2026 | Sophos PureMessage Scanner service (PMScanner.exe) in PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (message queue delay and incomplete spam rule update) via a crafted (1) RTF or (2) PDF file. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Exjune Office Message System | 22/5/2009 | 16/6/2026 | exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request. NOTE: some of these details are obtained from third party information. |