Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | ISS Blackice Agent | 4/10/2002 | 16/6/2026 | BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass intended firewall restrictions. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Blackboard | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi. | |
| Modificada | Media (5.5) | 1.3% | 💥 Exploit | Blackberry QNX Neutrino Real-time Operating System | 12/8/2002 | 16/6/2026 | Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility. | |
| Modificada | Media (5) | 2.6% | — | Black TIE Project | 26/7/2002 | 16/6/2026 | categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message. | |
| Modificada | Alta (7.5) | 3.7% | — | ISS Blackice AgentISS Blackice DefenderISS Realsecure Server Sensor | 29/5/2002 | 16/6/2026 | Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a flood of large ICMP ping packets. | |
| Modificada | Alta (7.5) | 4.2% | — | Selom Ofori Blackmoon FTP Server | 25/3/2002 | 16/6/2026 | Buffer overflow in BlackMoon FTP Server 1.0 through 1.5 allows remote attackers to execute arbitrary code via a long argument to (1) USER, (2) PASS, or (3) CWD. | |
| Modificada | Alta (7.5) | 1.5% | — | Blackboard Courseinfo | 18/7/2000 | 16/6/2026 | BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl. | |
| Modificada | Baja (2.1) | 0.35% | — | Blackboard Courseinfo | 10/7/2000 | 16/6/2026 | Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords. | |
| Modificada | Alta (7.5) | 1.3% | — | ISS Blackice AgentISS Blackice Defender | 22/6/2000 | 16/6/2026 | BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower. |