Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Adiscon Loganalyzer | 11/9/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index.php or (2) detail.php. | |
| Modificada | Media (4.3) | 3.6% | — | Zohocorp Manageengine Eventlog Analyzer | 29/8/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height, (3) url, (4) helpP, (5) tab, (6) module, (7) completeData, (8) RBBNAME, (9) TC, (10) rtype, (11)… | |
| Modificada | Media (4.3) | 3.5% | — | Zohocorp Manageengine Eventlog Analyzer | 25/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in Version 10 Build 10000. | |
| Modificada | Media (4.3) | 1.6% | — | Sonicwall AnalyzerSonicwall Global Management SystemSonicwall UMA Em5000 | 24/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the node_id parameter. | |
| Modificada | Media (4.3) | 2.8% | — | Sonicwall Global Management SystemSonicwall Analyzer | 14/2/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action. | |
| Modificada | Media (4.3) | 0.98% | — | Algosec Firewall Analyzer | 29/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in BusinessFlow/login in AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Algosec Firewall Analyzer | 29/1/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Baja (3.5) | 4.3% | 💥 Exploit | Sonicwall AnalyzerSonicwall Global Management SystemSonicwall UMA E5000 Firmware | 9/12/2013 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script or HTML via the (1) valfield_1 or (2)… | |
| Modificada | Baja (3.5) | 0.97% | — | Jenkins-ci Build Failure Analyzer | 25/11/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Fortinet Fortianalyzer FirmwareFortinet Fortianalyzer-1000dFortinet Fortianalyzer-2000bFortinet Fortianalyzer-200d+3 | 20/11/2013 | 17/6/2026 | cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks. | |
| Modificada | Media (4.3) | 14% | 💥 Exploit | Wptrafficanalyzer Trafficanalyzer | 10/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the aoid parameter. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Manageengine Firewall Analyzer | 10/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Media (4.3) | 7.7% | 💥 Exploit | Manageengine Firewall Analyzer | 10/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) tab parameter to createAnomaly.do; (3) url, (4) subTab, or (5) tab parameter to mindex.do; (6) tab parameter to index2.do; or (7) port… | |
| Modificada | Media (4.3) | 1.2% | — | Adiscon Loganalyzer | 20/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Adiscon LogAnalyzer before 3.4.4 and 3.5.x before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter in a Search action. | |
| Modificada | Media (4.3) | 1.1% | — | Hitachi IT Operations Analyzer | 24/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hitachi IT Operations Analyzer 02-01, 02-51 through 02-51-01, and 02-53 through 02-53-02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | — | Manageengine Eventlog Analyzer | 27/9/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile, (5) load, (6) type, or (7) tab parameter to INDEX.do, the (8) reported parameter to INDEX2.do, the (9) gId… | |
| Modificada | Alta (7.5) | 2.2% | — | Manageengine Eventlog Analyzer | 27/9/2011 | 16/6/2026 | Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.exe process crash) or possibly execute arbitrary code via a long Syslog PRI message header to UDP port (1) 513 or (2) 514. Fixed in 7.2 Build 7020. | |
| Modificada | Alta (10) | 6.8% | — | BMC Performance Analysis FOR ServersBMC Performance Assurance FOR ServersBMC Performance Assurance FOR Virtual ServersBMC Performance Analyzer FOR Servers+2 | 10/2/2011 | 16/6/2026 | Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10; and Capacity Management… | |
| Modificada | Media (4.3) | 1.0% | — | Futomi Access Analyzer CGI | 13/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in futomi CGI Cafe Access Analyzer CGI Professional, and Standard 4.0.2 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 0.87% | — | Webtrends LOG Analyzer | 5/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue. | |
| Modificada | Media (4.3) | 1.6% | — | Manageengine Netflow Analyzer | 6/11/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in jspui/index.jsp in ManageEngine Netflow Analyzer 7.5 build 7500 allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) section parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Alta (7.5) | 1.7% | — | Futomi CGI Cafe Access Analyzer CGI | 1/4/2009 | 16/6/2026 | Unspecified vulnerability in futomi's CGI Cafe Access Analyzer CGI Professional Version 4.11.5 and earlier allows remote attackers to gain administrative privileges via unknown vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Futomi Access Analyzer CGI | 19/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in futomi's CGI Cafe Access Analyzer CGI Standard Version 3.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (5.8) | 1.0% | — | Futomi Access Analyzer CGI | 2/1/2009 | 16/6/2026 | futomi CGI Cafe Access Analyzer CGI Standard 4.0.1 and earlier and Access Analyzer CGI Professional 4.11.3 and earlier use a predictable session id, which makes it easier for remote attackers to hijack sessions, and obtain sensitive information about analysis results, via a modified id. | |
| Modificada | Alta (7.2) | 1.00% | 💥 Exploit | Eset Software System Analyzer Tool | 6/10/2008 | 16/6/2026 | The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via a certain METHOD_NEITHER IOCTL request to \Device\esiasdrv that overwrites a pointer. |