Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.9% | — | Hitachi Cosminexus Application ServerHitachi Cosminexus TpbrokerHitachi TpbrokerHitachi Tpbroker Developer+1 | 9/7/2007 | 16/6/2026 | Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request. | |
| Modificada | Media (4.3) | 1.2% | — | Hitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB ClientHitachi Ucosminexus Collaboration Portal | 5/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Collaboration - File Sharing 01-20 up to 01-20-/B and 01-30 up to 01-30-/B in Hitachi Groupmax Collaboration Portal up to 07-30-/D, Groupmax Collaboration Web Client - Forum/File Sharing up to 07-30-/C, uCosminexus Collaboration Portal up to 06-30-/D, and uCosminexus… | |
| Modificada | Media (5) | 1.2% | — | Hitachi Cosminexus Component ContainerHitachi Electronic Form WorkflowHitachi Ucosminexus Application ServerHitachi Ucosminexus Developer+3 | 3/4/2007 | 16/6/2026 | Unspecified vulnerability in Hitachi Cosminexus Component Container 07-00 through 07-00-10, and 07-10 through 07-10-03, as used in uCosminexus Application Server Enterprise and Standard; uCosminexus Service Platform; uCosminexus Developer Standard and Professional; uCosminexus Service Architect; Electronic Form… | |
| Modificada | Media (6.8) | 1.2% | — | Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB ClientHitachi Ucosminexus Collaboration Portal+1 | 31/3/2007 | 16/6/2026 | SQL injection vulnerability in Hitachi Collaboration - Online Community Management 01-00 through 01-30, as used in Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, and uCosminexus Content Manager, allows remote attackers to execute… | |
| Modificada | Media (6.8) | 1.2% | — | Hitachi Cosminexus Application ServerHitachi Cosminexus Application Server Version 5Hitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+15 | 26/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps. | |
| Modificada | Media (6.8) | 1.4% | — | Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client | 13/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Groupmax Collaboration Portal and Web Client before 07-20-/D, and uCosminexus Collaboration Portal and Forum/File Sharing before 06-20-/C, allow remote attackers to "execute malicious scripts" via unknown vectors (aka HS06-014-01). | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Jonathan Beckett Pluggedout Nexus | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter. | |
| Modificada | Media (4.6) | 0.34% | — | Nexus Concepts DEV Hound | 23/12/2005 | 16/6/2026 | Nexus Concepts Dev Hound 2.24 and earlier stores username and password information in cleartext in the devhound.tdbd file, which allows local users to gain privileges. | |
| Modificada | Media (4.3) | 1.2% | — | Nexus Concepts DEV Hound | 23/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Nexus Concepts Dev Hound 2.24 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple unspecified user input fields. | |
| Modificada | Media (5) | 1.4% | — | Nexus Concepts DEV Hound | 23/12/2005 | 16/6/2026 | Nexus Concepts Dev Hound 2.24 and earlier allows remote attackers to obtain the installation path via a URL containing a non-existent .dll file. | |
| Modificada | Alta (7.8) | 2.0% | — | Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client | 17/12/2005 | 16/6/2026 | Unspecified vulnerability in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to cause a denial of service of unspecified impact via repeated invalid requests to the… | |
| Modificada | Media (4.3) | 1.4% | — | Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client | 17/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to inject arbitrary web script or HTML via the (1) Schedule… | |
| Modificada | Media (4.3) | 1.2% | — | Jonathan Beckett Pluggedout Nexus | 7/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Location, (2) Last Name, and (3) First Name parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | Jonathan Beckett Pluggedout Nexus | 7/12/2005 | 16/6/2026 | SQL injection vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) Location, (2) Last Name, and (3) First Name parameters. | |
| Modificada | Baja (2.6) | 6.5% | — | Hitachi Cosminexus Application ServerApache Tomcat | 6/10/2005 | 16/6/2026 | The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body… | |
| Modificada | Alta (10) | 3.6% | — | Neteyes Nexusway | 11/5/2005 | 16/6/2026 | The SSH module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via shell metacharacters in arguments to certain commands, as demonstrated using ping and traceroute. | |
| Modificada | Alta (7.5) | 1.8% | — | Neteyes Nexusway | 11/5/2005 | 16/6/2026 | The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie. | |
| Modificada | Alta (10) | 3.9% | — | Neteyes NexuswayAI | 11/5/2005 | 16/6/2026 | The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi. | |
| Modificada | Media (5) | 1.5% | — | Hitachi Cosminexus Portal FrameworkAI | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library. | |
| Modificada | Alta (7.5) | 3.4% | — | Hitachi Cosminexus EnterpriseHitachi Cosminexus ServerMacromedia ColdfusionMacromedia Jrun | 31/12/2004 | 16/6/2026 | JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session. | |
| Modificada | Media (5) | 4.1% | — | Hitachi Cosminexus EnterpriseHitachi Cosminexus ServerMacromedia ColdfusionMacromedia Jrun | 5/10/2004 | 16/6/2026 | The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm". |