Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

370 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.9%—Jexperts Channel Platform13/11/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in JExperts Channel Platform 5.0.33_CCB allow remote attackers to inject arbitrary web script or HTML via the (1) usuario.nome variable in an editarUsuario action to usuario.do or (2) titulo.form variable in a novoChamado action to ticket.do.
ModificadaMedia (5.4)0.27%—Webpromoexperts20/10/201417/6/2026
The WebPromoExperts (aka ua.com.webpromoexperts) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5)1.0%—Aveva ClearscadaSchneider-electric Scada Expert Clearscada18/9/201417/6/2026
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm.
ModificadaMedia (5)1.6%—Aveva ClearscadaSchneider-electric Scada Expert Clearscada18/9/201417/6/2026
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.
ModificadaBaja (3.5)1.3%—Aveva ClearscadaSchneider-electric Scada Expert Clearscada18/9/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)57%💥 ExploitManageengine Device Expert4/9/201417/6/2026
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.
ModificadaAlta (7.8)1.8%—Schneider-electric CitectscadaSchneider-electric Powerlogic ScadaSchneider-electric Struxureware Powerscada ExpertSchneider-electric Struxureware Scada Expert Vijeo Citect26/2/201416/6/2026
Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of…
ModificadaBaja (1.9)0.48%—IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager25/9/201316/6/2026
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an…
ModificadaMedia (4.3)1.1%—IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager25/9/201316/6/2026
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.
ModificadaBaja (3.5)0.92%—IBM Data Studio WEB ConsoleIBM DB2 Recovery ExpertIBM Infosphere Optim Configuration ManagerIBM Optim Performance Manager25/9/201316/6/2026
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown…
ModificadaAlta (7.5)0.91%💥 ExploitJoomla COM Elite Experts9/10/201116/6/2026
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showExpertProfileDetailed action to index.php.
ModificadaMedia (4.3)0.87%—Iplanet Webexpert5/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
ModificadaMedia (4.3)0.87%—Alentum Weblog Expert5/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in WebLogExpert allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
ModificadaAlta (8.8)2.7%💥 ExploitVisagesoft Expert PDF Editorx20/3/200916/6/2026
Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows remote attackers to create or overwrite arbitrary files via the first argument to the extractPagesToFile method.
ModificadaMedia (6.8)0.91%💥 ExploitExperts28/11/200816/6/2026
SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the question_id parameter.
ModificadaAlta (8.8)2.8%💥 ExploitVisagesoft Expert PDF Viewer Activex4/11/200816/6/2026
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAsBitmap method.
ModificadaAlta (7.5)0.99%💥 ExploitPopscript.com Expert Advisor18/7/200716/6/2026
SQL injection vulnerability in index.php in Expert Advisor allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.5%—Archivexpert11/4/200716/6/2026
Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .tar.gz, (5) .zip, or (6) .tar file.
ModificadaAlta (7.5)4.0%—Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server30/8/200516/6/2026
Stack-based buffer overflow in the ACE archive decompression library (vrAZace.dll) in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall, when compressed file scanning is enabled, allows remote attackers to execute arbitrary code via an ACE archive that contains a…
ModificadaMedia (5)3.5%—Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server23/8/200516/6/2026
Directory traversal vulnerability in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall allows remote attackers to overwrite arbitrary files via ".." sequences in filenames contained in (1) ACE, (2) ARJ, (3) CAB, (4) LZH, (5) RAR, (6) TAR and (7) ZIP files.