Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.27% | — | Suse Linux Enterprise Server | 24/1/2020 | 17/6/2026 | The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to… | |
| Modificada | Media (6.5) | 3.6% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+4 | 23/1/2020 | 17/6/2026 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. | |
| Modificada | Alta (8.8) | 39% | 💥 Exploit | PhpmyadminSuse Linux Enterprise ServerDebian Linux | 9/1/2020 | 17/6/2026 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server. | |
| Modificada | Alta (8.8) | 1.1% | — | Obs-serverSuse Linux Enterprise Server | 2/1/2020 | 16/6/2026 | obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation. | |
| Modificada | Alta (7.5) | 3.2% | — | EglibcNovell Suse Linux Enterprise ServerDebian LinuxCanonical Ubuntu Linux+1 | 31/12/2019 | 16/6/2026 | The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. | |
| Modificada | Alta (7.8) | 0.51% | — | QemuDebian LinuxNovell Open Desktop ServerNovell Open Enterprise Server | 30/12/2019 | 16/6/2026 | A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus… | |
| Modificada | Alta (8.8) | 2.0% | — | Canonical Cloud-initDebian LinuxSuse Linux Enterprise Server | 25/11/2019 | 16/6/2026 | An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data. | |
| Modificada | Alta (7.5) | 2.3% | — | Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+23 | 15/11/2019 | 17/6/2026 | A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. | |
| Modificada | Media (5.5) | 8.9% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365Microsoft Office Online Server+2 | 12/11/2019 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'. | |
| Modificada | Media (6.5) | 5.7% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 12/11/2019 | 17/6/2026 | An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain SMB hashes.The security update… | |
| Modificada | Media (6.1) | 49% | — | Wikidsystems 2FA Enterprise Server | 17/10/2019 | 17/6/2026 | A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. The usr parameter is vulnerable: the reflected cross-site scripting occurs immediately after the user is… | |
| Modificada | Alta (8.8) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter. | |
| Modificada | Alta (8.8) | 0.94% | — | Wikidsystems 2FA Enterprise Server | 17/10/2019 | 17/6/2026 | A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete groups; or (3) create, delete, enable, or disable normal users or devices. | |
| Modificada | Alta (8.8) | 1.7% | — | Wikidsystems 2FA Enterprise Server | 17/10/2019 | 17/6/2026 | A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary SQL commands via the processPref.jsp key parameter. | |
| Modificada | Media (6.1) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups.jsp. The groupName parameter is vulnerable: the reflected cross-site scripting occurs immediately after the group is… | |
| Modificada | Media (6.1) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is visited. The rendered_message column is retrieved and displayed, unsanitized, on Logs.jsp. A remote attack can populate… | |
| Modificada | Media (6.1) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userPreregistration.jsp. The preRegistrationData parameter is vulnerable: a reflected cross-site scripting occurs immediately… | |
| Modificada | Alta (8.8) | 2.1% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL query constructed in the buildSearchWhereClause function. | |
| Modificada | Media (6.5) | 2.6% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Foundation | 10/10/2019 | 17/6/2026 | An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329. | |
| Modificada | Media (5.4) | 1.5% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Foundation | 10/10/2019 | 17/6/2026 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1330. | |
| Modificada | Media (5.4) | 1.5% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Foundation | 10/10/2019 | 17/6/2026 | A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. | |
| Modificada | Media (5.4) | 1.5% | — | Microsoft Sharepoint Enterprise Server | 10/10/2019 | 17/6/2026 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. | |
| Modificada | Alta (7.1) | 0.34% | — | Suse Linux Enterprise Server | 7/10/2019 | 17/6/2026 | The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by… | |
| Modificada | Media (6.1) | 0.78% | — | Microfocus Enterprise DeveloperMicrofocus Enterprise Server | 2/10/2019 | 17/6/2026 | Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2. The vulnerability could be exploited to redirect a user to a malicious page or forge certain types of web requests. | |
| Modificada | Alta (8.8) | 8.3% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 11/9/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295. |