Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

367 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.1%—Secure Elements C5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read sensitive vulnerability information.
ModificadaMedia (5)2.2%—Secure Elements C5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large number of forged client registration messages.
ModificadaMedia (5)3.7%—Secure Elements Class 5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1) execute arbitrary code on a client or (2) forge messages to the server.
ModificadaMedia (5)1.9%—Secure Elements C5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attackers to send messages to a protected asset without knowing the proper CEID.
ModificadaMedia (5)2.4%—Secure Elements Class 5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER messages, which leads to a buffer overflow (probably an over-read).
ModificadaMedia (5)1.9%—Secure Elements Class 5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages.
ModificadaAlta (7.5)2.2%—Secure Elements C5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain access to the server.
ModificadaMedia (5)2.2%—Secure Elements Class 5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start" messages that cause AVR to connect to arbitrary hosts.
ModificadaMedia (5)2.6%—Secure Elements Class 5 Enterprise Vulnerability Management31/5/200616/6/2026
Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote attackers to modify and replay messages.
ModificadaMedia (4.6)0.33%—Winability Folder Guard18/2/200616/6/2026
WinAbility Folder Guard 4.11 allows local users to gain unauthorized access to certain capabilities of the application by renaming or moving the password file (FGuard.FGP), which disables the password requirement.
ModificadaMedia (4.6)0.33%—Winability Folder Guard17/11/200516/6/2026
Folder Guard allows local users to bypass protections by running from or installing to the temporary files directory.
ModificadaBaja (2.1)0.36%—High Availability Linux Project Heartbeat12/7/200516/6/2026
High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
ModificadaAlta (7.8)2.0%—Code-crafters Ability Mail Server31/12/200416/6/2026
The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.
ModificadaMedia (4.3)1.9%💥 ExploitAbility Mail ServerAI31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.
ModificadaMedia (5)67%💥 ExploitCode-crafters Ability Server22/10/200416/6/2026
Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.
ModificadaAlta (7.5)15%💥 ExploitCode-crafters Ability Server22/10/200416/6/2026
Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.
ModificadaMedia (5)1.3%—IBM High Availability Cluster Multiprocessing27/6/200116/6/2026
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.
Orbitaley — Vulnerabilidades