Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
383 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 8.2% | 💥 Exploit | Dell Netvault Backup | 14/8/2015 | 17/6/2026 | Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request. | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Image Vault Firmware | 4/8/2015 | 16/6/2026 | GE Healthcare Centricity Image Vault 3.x has a password of (1) gemnet for the administrator account, (2) webadmin for the webadmin administrator account of the ASACA DVD library, (3) an empty value for the gemsservice account of the Ultrasound Database, and possibly (4) gemnet2002 for the gemnet2002 account of the… | |
| Modificada | Alta (10) | 6.0% | — | Dell Netvault Backup | 29/5/2015 | 17/6/2026 | Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 2.4% | — | Alienvault Unified Security Management | 1/5/2015 | 17/6/2026 | The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plugin configuration file (.cfg). | |
| Modificada | Media (6.4) | 1.1% | — | Tibco Managed File Transfer Internet ServerTibco Managed File Transfer Command CenterTibco SlingshotTibco Vault | 21/11/2014 | 17/6/2026 | TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before 1.1.1 allow remote attackers to obtain sensitive information or modify data by leveraging agent access. | |
| Modificada | Alta (8.8) | 57% | 💥 Exploit | Openmediavault | 29/9/2014 | 16/6/2026 | The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter. | |
| Modificada | Media (5.4) | 0.29% | — | NQ Vault-hide SMS Pics & Videos | 9/9/2014 | 17/6/2026 | The Vault-Hide SMS, Pics & Videos (aka com.netqin.ps) application 5.0.14.22 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.5) | 21% | 💥 Exploit | Alienvault Open Source Security Information Management | 21/8/2014 | 17/6/2026 | SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Alienvault Open Source Security Information Management | 21/8/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805. | |
| Modificada | Alta (7.5) | 1.3% | — | Alienvault Open Source Security Information Management | 21/8/2014 | 17/6/2026 | SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter. | |
| Modificada | Alta (10) | 3.7% | — | Alienvault Open Source Security Information Management | 21/8/2014 | 17/6/2026 | The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors. | |
| Modificada | Alta (7.8) | 7.4% | 💥 Exploit | Alienvault Open Source Security Information Management | 18/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request. | |
| Modificada | Alta (10) | 5.8% | — | Alienvault Open Source Security Information Management | 18/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key. | |
| Modificada | Alta (10) | 7.3% | — | Alienvault Open Source Security Information Management | 18/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Alienvault Open Source Security Information Management | 13/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804. | |
| Modificada | Alta (10) | 72% | 💥 Exploit | Alienvault Open Source Security Information Management | 13/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4) sync_rserver, or (5) set_ossim_setup framework_ip request, a different vulnerability than… | |
| Modificada | Alta (9) | 3.0% | — | Dell Powervault Ml6000 FirmwareDell Powervault Ml6000Quantum Scalar I500 FirmwareQuantum Scalar I500 | 2/6/2014 | 17/6/2026 | logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter. | |
| Modificada | Media (5) | 1.8% | — | Tibco SlingshotTibco VaultTibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 30/4/2014 | 17/6/2026 | TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before 1.0.1 allow remote attackers to obtain sensitive information via a crafted HTTP request. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Alienvault Open Source Security Information Management | 9/10/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3)… | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Alienvault Open Source Security Information Management | 20/8/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to… | |
| Modificada | Media (4.3) | 1.8% | — | Alienvault Open Source Security Information Management | 15/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to… | |
| Modificada | Alta (7.8) | 0.41% | — | Symantec Enterprise Vault FOR File System Archiving | 26/3/2013 | 16/6/2026 | Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Alienvault Open Source Security Information Management | 3/7/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an… | |
| Modificada | Media (6.5) | 1.4% | 💥 Exploit | Alienvault Open Source Security Information Management | 3/7/2012 | 16/6/2026 | SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter. | |
| Modificada | Alta (7.5) | 3.5% | — | Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+5 | 22/3/2012 | 16/6/2026 | The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier… |