Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.9% | — | Acquia CommonsAcquia Commons Group | 16/7/2013 | 16/6/2026 | The Commons Group module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors. | |
| Modificada | Media (6.8) | 0.68% | — | Apache Commons Fileupload | 15/3/2013 | 7/10/2026 | The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. | |
| Modificada | Media (5) | 1.4% | — | Acquia Commons | 31/10/2012 | 16/6/2026 | The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain sensitive information… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Michau Enterprises LLC Commonsense CMS | 9/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in SenseSites CommonSense CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) special.php, (2) article.php, or (3) cat2.php. | |
| Modificada | Baja (2.1) | 1.1% | — | Creative Commons Module Project Creativecommons | 26/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Creative Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote authenticated users with the administer creative commons permission to inject arbitrary web script or HTML via the (1) creativecommons_user_message or (2)… | |
| Modificada | Media (6.5) | 1.1% | — | Mcafee Common Management Agent | 22/8/2012 | 16/6/2026 | McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenticated users to overwrite arbitrary files by accessing a report-writing ActiveX control COM object. | |
| Modificada | Media (4.3) | 2.5% | — | Debian Php5-commonDebian LinuxCanonical Php5Canonical Ubuntu Linux | 7/8/2012 | 16/6/2026 | The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which… | |
| Modificada | Media (5) | 13% | — | Apache Commons Compress | 29/6/2012 | 16/6/2026 | Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs. | |
| Modificada | Media (4.3) | 1.2% | — | Ciscoworks Common Services | 3/5/2012 | 16/6/2026 | CRLF injection vulnerability in autologin.jsp in Cisco CiscoWorks Common Services 4.0, as used in Cisco Prime LAN Management Solution and other products, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter, aka Bug ID CSCtu18693. | |
| Modificada | Media (5.3) | 4.9% | — | Oracle SUN Storage Common Array ManagerMortbay Jetty | 30/12/2011 | 16/6/2026 | Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Michau Enterprises Sensesites Commonsense CMS | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | |
| Modificada | Media (5) | 1.1% | — | Ciscoworks Common Services | 22/10/2011 | 16/6/2026 | The Sybase SQL Anywhere database component in Cisco CiscoWorks Common Services 3.x and 4.x before 4.1 allows remote attackers to obtain potentially sensitive information about the engine name and database port via an unspecified request to UDP port 2638, aka Bug ID CSCsk35018. | |
| Modificada | Alta (9) | 15% | — | Ciscoworks Common ServicesMicrosoft Windows | 20/10/2011 | 16/6/2026 | The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management Solution, Cisco Security Manager, Cisco Unified Service Monitor, Cisco Unified Operations Manager, CiscoWorks QoS Policy Manager, and CiscoWorks Voice Manager, allows remote authenticated users to… | |
| Modificada | Media (5) | 7.2% | — | Apache TomcatApache Commons Daemon | 15/8/2011 | 16/6/2026 | native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to… | |
| Modificada | Media (6.8) | 41% | 💥 Exploit | Ciscoworks Common Services | 20/5/2011 | 16/6/2026 | Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, aka Bug ID CSCto35577. | |
| Modificada | Media (4.3) | 5.2% | 💥 Exploit | Ciscoworks Common Services | 20/5/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the device parameter, aka Bug ID CSCto12704. | |
| Modificada | Media (6.9) | 0.37% | — | IBM Rational ClearcaseIBM Rational ClearquestIBM Rational Common Licensing | 29/3/2011 | 16/6/2026 | Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a Trojan horse HTML document in the My Computer zone. | |
| Modificada | Media (6.8) | 4.1% | — | Debian Tex-commonCanonical Ubuntu LinuxDebian Linux | 25/3/2011 | 16/6/2026 | The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a… | |
| Modificada | Alta (10) | 1.6% | — | IBM Tivoli Integrated PortalIBM Tivoli Common Reporting | 1/2/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in IBM Tivoli Integrated Portal (TIP) 1.1.1.1, as used in IBM Tivoli Common Reporting (TCR) 1.2.0 before Interim Fix 9, have unknown impact and attack vectors, related to "security vulnerabilities of Websphere Application Server bundled within" and "many internal defects and APARs." | |
| Modificada | Alta (10) | 6.0% | — | Ciscoworks Common ServicesCiscoworks LAN Management SolutionCisco QOS Policy ManagerCisco Security Manager+3 | 29/10/2010 | 16/6/2026 | Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352. | |
| Modificada | Media (4.3) | 1.0% | — | Common1 Moobbs2 | 31/8/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Free CGI Moo moobbs2 before 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Common1 Moobbs | 31/8/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Free CGI Moo moobbs before 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Sensesites Commonsense CMS | 23/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in CommonSense CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Paperthin Commonspot Content Server | 2/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (4.3) | 2.4% | — | Broadcom Anti-virusBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti-virus SDKBroadcom Common Services+29 | 13/10/2009 | 16/6/2026 | Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to… |