Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | Stalker Communigate PRO | 31/12/2003 | 16/6/2026 | CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer. | |
| Modificada | Crítica (9.8) | 1.6% | — | Pedestalsoftware Integrity Protection Driver | 31/12/2003 | 16/6/2026 | Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst… | |
| Modificada | Baja (2.1) | 0.35% | — | Pedestal Software Integrity Protection Driver | 31/12/2002 | 16/6/2026 | Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink. | |
| Modificada | Media (5) | 1.5% | — | Stalker Communigate PRO | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding… | |
| Modificada | Baja (2.1) | 0.43% | — | Pedestal Software Integrity Protection Driver | 31/12/2002 | 16/6/2026 | restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time. | |
| Modificada | Alta (7.5) | 4.0% | — | Businessobjects Crystal Reports | 10/1/2001 | 16/6/2026 | Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Stalker Communigate PRO | 11/12/2000 | 23/9/2026 | POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks. | |
| Modificada | Baja (1.2) | 0.30% | — | Helix Code Gnome Installer | 20/10/2000 | 16/6/2026 | Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config. | |
| Modificada | Media (6.2) | 0.31% | — | Helix Code Go-gnome Pre-installer | 20/10/2000 | 16/6/2026 | The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files. | |
| Modificada | Baja (2.6) | 1.3% | — | Stalkerlab Mailers | 20/10/2000 | 16/6/2026 | CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Stalker Communigate PRO | 3/4/2000 | 16/6/2026 | The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Media (5) | 1.5% | — | Stalker Communigate PRO | 3/12/1999 | 16/6/2026 | Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Stalker Internet Mail Server | 8/4/1998 | 16/6/2026 | Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command. |