Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.5%—Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+522/3/201216/6/2026
The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier…
ModificadaMedia (6)1.0%—Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+322/3/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to hijack the authentication of users for requests…
ModificadaBaja (3.5)1.2%—Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+322/3/201216/6/2026
Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to inject arbitrary web script or HTML via unspecified…
ModificadaMedia (5)2.1%—Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+322/3/201216/6/2026
Absolute path traversal vulnerability in logShow.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to read arbitrary files via a full pathname in the file parameter.
ModificadaMedia (4.3)1.1%—Cyber-ark Password Vault WEB Access5/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in Cyber-Ark Password Vault Web Access (PVWA) 5.0 and earlier, 5.5 through 5.5 patch 4, and 6.0 through 6.0 patch 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)3.3%—Oracle Audit Vault19/1/201116/6/2026
Unspecified vulnerability in the Audit Vault component in Oracle Audit Vault 10.2.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party…
ModificadaAlta (7.5)0.97%💥 ExploitAlienvault Open Source Security Information Management21/12/200916/6/2026
SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary SQL commands via the id_document parameter.
ModificadaAlta (7.5)1.6%—Alienvault Open Source Security Information Management21/12/200916/6/2026
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.
ModificadaAlta (7.5)3.0%—Alienvault Open Source Security Information Management21/12/200916/6/2026
Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a…
ModificadaAlta (7.5)4.8%💥 ExploitAlienvault Open Source Security Information Management21/12/200916/6/2026
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the uniqueid parameter to (1) wcl.php, (2) storage_graphs.php, (3) storage_graphs2.php, (4) storage_graphs3.php, and (5)…
ModificadaMedia (5)1.7%—Bakbone Netvault29/9/200916/6/2026
npvmgr.exe in BakBone NetVault Backup 8.22 Build 29 allows remote attackers to cause a denial of service (daemon crash) via a packet to (1) TCP or (2) UDP port 20031 with a large value in an unspecified size field, which is not properly handled in a malloc operation. NOTE: some of these details are obtained from third…
ModificadaMedia (5)2.3%—Alienvault Ossim28/9/200916/6/2026
Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to bypass authentication, and read graphs or infrastructure information, via a direct request to (1) graphs/alarms_events.php or (2) host/draw_tree.php.
ModificadaMedia (4.3)1.5%💥 ExploitAlienvault Ossim28/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).
ModificadaMedia (6.5)0.85%💥 ExploitAlienvault Ossim28/9/200916/6/2026
Multiple SQL injection vulnerabilities in Open Source Security Information Management (OSSIM) before 2.1.2 allow remote authenticated users to execute arbitrary SQL commands via the id_document parameter to (1) repository_document.php, (2) repository_links.php, and (3) repository_editdocument.php in repository/; the…
ModificadaMedia (5)0.97%—Xenu BY Datavault21/9/200916/6/2026
DataVault.Tesla/Impl/TypeSystem/AssociationHelper.cs in datavault allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of an [ (open bracket) followed by many commas, related to a certain regular expression, aka a "ReDoS" vulnerability.
ModificadaMedia (6.8)1.9%—Sony Micro Vault Fingerprint Access Software10/9/200716/6/2026
Sony Micro Vault Fingerprint Access Software, as distributed with Sony Micro Vault USM-F USB flash drives, installs a driver that hides a directory under %WINDIR%, which might allow remote attackers to bypass malware detection by placing files in this directory.
ModificadaAlta (10)15%💥 ExploitAlpha Centauri Software Sidvault Ldap Server28/8/200716/6/2026
Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind.
ModificadaAlta (10)6.8%—Bakbone Netvault Reporter30/7/200716/6/2026
Multiple heap-based buffer overflows in (1) clsscheduler.exe (aka scheduler client) and (2) srvscheduler.exe (aka scheduler server) in BakBone NetVault Reporter 3.5 before Update4 allow remote attackers to execute arbitrary code via long filename arguments in HTTP requests.
ModificadaAlta (10)13%💥 ExploitBakbone NetvaultFirebirdsql Firebird12/6/200716/6/2026
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."
ModificadaAlta (7.5)4.5%💥 ExploitIsode M-vault Server15/2/200616/6/2026
Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.
ModificadaAlta (7.5)3.0%💥 ExploitBakbone Netvault14/5/200516/6/2026
Heap-based buffer overflow in the demo version of Bakbone Netvault, and possibly other versions, allows remote attackers to execute arbitrary commands via a large packet to port 20031.
ModificadaMedia (4.6)1.00%💥 ExploitBakbone Netvault3/5/200516/6/2026
nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.
ModificadaAlta (10)57%💥 ExploitBakbone Netvault2/5/200516/6/2026
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long Name entry in the configure.cfg file.
ModificadaMedia (5)2.2%—HP Virtualvault31/1/200516/6/2026
Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.
ModificadaAlta (10)34%—Apache Http ServerHP VirtualvaultHP WebproxyIBM Http Server+36/8/200416/6/2026
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
Orbitaley — Vulnerabilidades