Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

383 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)8.2%💥 ExploitDell Netvault Backup14/8/201517/6/2026
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
ModificadaAlta (10)1.7%—Gehealthcare Centricity Image Vault Firmware4/8/201516/6/2026
GE Healthcare Centricity Image Vault 3.x has a password of (1) gemnet for the administrator account, (2) webadmin for the webadmin administrator account of the ASACA DVD library, (3) an empty value for the gemsservice account of the Ultrasound Database, and possibly (4) gemnet2002 for the gemnet2002 account of the…
ModificadaAlta (10)6.0%—Dell Netvault Backup29/5/201517/6/2026
Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow.
ModificadaAlta (9.3)2.4%—Alienvault Unified Security Management1/5/201517/6/2026
The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plugin configuration file (.cfg).
ModificadaMedia (6.4)1.1%—Tibco Managed File Transfer Internet ServerTibco Managed File Transfer Command CenterTibco SlingshotTibco Vault21/11/201417/6/2026
TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before 1.1.1 allow remote attackers to obtain sensitive information or modify data by leveraging agent access.
ModificadaAlta (8.8)57%💥 ExploitOpenmediavault29/9/201416/6/2026
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.
ModificadaMedia (5.4)0.29%—NQ Vault-hide SMS Pics & Videos9/9/201417/6/2026
The Vault-Hide SMS, Pics & Videos (aka com.netqin.ps) application 5.0.14.22 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.5)21%💥 ExploitAlienvault Open Source Security Information Management21/8/201417/6/2026
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (10)15%💥 ExploitAlienvault Open Source Security Information Management21/8/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.
ModificadaAlta (7.5)1.3%—Alienvault Open Source Security Information Management21/8/201417/6/2026
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter.
ModificadaAlta (10)3.7%—Alienvault Open Source Security Information Management21/8/201417/6/2026
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.
ModificadaAlta (7.8)7.4%💥 ExploitAlienvault Open Source Security Information Management18/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.
ModificadaAlta (10)5.8%—Alienvault Open Source Security Information Management18/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key.
ModificadaAlta (10)7.3%—Alienvault Open Source Security Information Management18/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request.
ModificadaAlta (10)13%💥 ExploitAlienvault Open Source Security Information Management13/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804.
ModificadaAlta (10)72%💥 ExploitAlienvault Open Source Security Information Management13/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4) sync_rserver, or (5) set_ossim_setup framework_ip request, a different vulnerability than…
ModificadaAlta (9)3.0%—Dell Powervault Ml6000 FirmwareDell Powervault Ml6000Quantum Scalar I500 FirmwareQuantum Scalar I5002/6/201417/6/2026
logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter.
ModificadaMedia (5)1.8%—Tibco SlingshotTibco VaultTibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server30/4/201417/6/2026
TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before 1.0.1 allow remote attackers to obtain sensitive information via a crafted HTTP request.
ModificadaAlta (7.5)19%💥 ExploitAlienvault Open Source Security Information Management9/10/201316/6/2026
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3)…
ModificadaAlta (7.5)1.4%💥 ExploitAlienvault Open Source Security Information Management20/8/201316/6/2026
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to…
ModificadaMedia (4.3)1.8%—Alienvault Open Source Security Information Management15/8/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to…
ModificadaAlta (7.8)0.41%—Symantec Enterprise Vault FOR File System Archiving26/3/201316/6/2026
Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program.
ModificadaMedia (4.3)2.2%💥 ExploitAlienvault Open Source Security Information Management3/7/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an…
ModificadaMedia (6.5)1.4%💥 ExploitAlienvault Open Source Security Information Management3/7/201216/6/2026
SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter.
ModificadaAlta (7.5)3.5%—Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+522/3/201216/6/2026
The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier…
Orbitaley — Vulnerabilidades