Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

481 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)52%💥 ExploitHP Identity Driven ManagerHP Procurve Manager16/9/201316/6/2026
UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified…
ModificadaAlta (10)71%💥 ExploitHP Identity Driven ManagerHP Procurve Manager16/9/201316/6/2026
UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified…
AnalizadaCrítica (9.8)79%⚠ Explotación activa💥 ExploitHP Application Lifecycle ManagementHP Procurve Manager16/9/201316/6/2026
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of…
ModificadaAlta (7.5)3.3%—HP Identity Driven ManagerHP Procurve Manager16/9/201316/6/2026
Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter.
ModificadaMedia (5)1.5%—Cisco Vc240 Network Bullet CameraCisco Video Surveillance Vc220 Network Dome Camera1/8/201316/6/2026
The Cisco VC220 and VC240 cameras allow remote attackers to cause a denial of service (WebUI outage) via crafted packets, aka Bug IDs CSCtf73188, CSCtf88059, CSCtf87951, CSCtf87908, and CSCtf88019.
ModificadaAlta (7.8)9.3%💥 ExploitCisco Video Surveillance Manager25/7/201316/6/2026
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID…
ModificadaAlta (9)8.3%💥 ExploitCisco Video Surveillance Manager25/7/201316/6/2026
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288.
ModificadaAlta (7.8)10%💥 ExploitCisco Video Surveillance Manager25/7/201316/6/2026
Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a crafted URL, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37163.
ModificadaAlta (7.1)3.1%—HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+116/7/201316/6/2026
Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors.
ModificadaAlta (10)10%—HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+116/7/201316/6/2026
Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors.
ModificadaMedia (4.3)0.96%—Cisco Video Surveillance Operations Manager14/6/201316/6/2026
Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490.
ModificadaMedia (6.5)7.0%💥 ExploitQnap Viostor Network Video RecorderQnap Surveillance Station PROQnap NAS7/6/201316/6/2026
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.
ModificadaMedia (5)1.3%—Qnap Viostor Network Video RecorderQnap Surveillance Station PROQnap NAS7/6/201316/6/2026
QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.
ModificadaMedia (6.8)1.5%—HP Procurve Switch SoftwareHP Procurve Switch 1700-24HP Procurve Switch 1700-828/3/201316/6/2026
Cross-site request forgery (CSRF) vulnerability on HP ProCurve 1700-8 (aka J9079A) switches with software before VA.02.09 and 1700-24 (aka J9080A) switches with software before VB.02.09 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaBaja (2.6)0.90%—Limesurvey12/2/201316/6/2026
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.
ModificadaMedia (4.3)1.2%—Limesurvey19/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.5)1.0%—Limesurvey19/9/201216/6/2026
SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)2.2%💥 ExploitLimesurvey15/9/201216/6/2026
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.
ModificadaBaja (3.7)1.2%—HP Procurve Switch 5400zlHP Procurve Switch 5400zl Management ModuleHP Procurve Switch 5406-44g-poe+-4sfpzlHP Procurve Switch 5406-48gzl+1012/4/201216/6/2026
HP ProCurve 5400 zl switches with certain serial numbers include a compact flash card that contains an unspecified virus, which might allow user-assisted remote attackers to execute arbitrary code on a PC by leveraging manual transfer of this card.
ModificadaMedia (4.3)1.5%💥 ExploitSellatsite Smart ASP Survey2/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter.
ModificadaAlta (7.8)1.2%—Cisco Video Surveillance 2421Cisco Video Surveillance 2500Cisco Video Surveillance SoftwareCisco Video Surveillance 260027/10/201116/6/2026
Cisco Video Surveillance 2421 and 2500 series cameras with software 1.1.x and 2.x before 2.4.0 and Video Surveillance 2600 series cameras with software before 4.2.0-13 allow remote attackers to cause a denial of service (device reload) by sending crafted RTSP packets over TCP, aka Bug IDs CSCtj96312, CSCtj39462, and…
ModificadaMedia (5)1.3%—Limesurvey23/9/201116/6/2026
LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/statistics.php and certain other files.
ModificadaMedia (5)3.5%💥 ExploitGeovision Digital Surveillance System12/9/201116/6/2026
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.
ModificadaAlta (9.3)45%💥 ExploitVisiwave Site Survey8/6/201116/6/2026
VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference.
ModificadaMedia (4.3)1.9%—Fubra Wp-survey-and-quiz-tool30/12/201016/6/2026
Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.
Orbitaley — Vulnerabilidades