Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 52% | 💥 Exploit | HP Identity Driven ManagerHP Procurve Manager | 16/9/2013 | 16/6/2026 | UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified… | |
| Modificada | Alta (10) | 71% | 💥 Exploit | HP Identity Driven ManagerHP Procurve Manager | 16/9/2013 | 16/6/2026 | UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified… | |
| Analizada | Crítica (9.8) | 79% | ⚠ Explotación activa💥 Exploit | HP Application Lifecycle ManagementHP Procurve Manager | 16/9/2013 | 16/6/2026 | HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of… | |
| Modificada | Alta (7.5) | 3.3% | — | HP Identity Driven ManagerHP Procurve Manager | 16/9/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter. | |
| Modificada | Media (5) | 1.5% | — | Cisco Vc240 Network Bullet CameraCisco Video Surveillance Vc220 Network Dome Camera | 1/8/2013 | 16/6/2026 | The Cisco VC220 and VC240 cameras allow remote attackers to cause a denial of service (WebUI outage) via crafted packets, aka Bug IDs CSCtf73188, CSCtf88059, CSCtf87951, CSCtf87908, and CSCtf88019. | |
| Modificada | Alta (7.8) | 9.3% | 💥 Exploit | Cisco Video Surveillance Manager | 25/7/2013 | 16/6/2026 | Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID… | |
| Modificada | Alta (9) | 8.3% | 💥 Exploit | Cisco Video Surveillance Manager | 25/7/2013 | 16/6/2026 | Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288. | |
| Modificada | Alta (7.8) | 10% | 💥 Exploit | Cisco Video Surveillance Manager | 25/7/2013 | 16/6/2026 | Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a crafted URL, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37163. | |
| Modificada | Alta (7.1) | 3.1% | — | HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+11 | 6/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors. | |
| Modificada | Alta (10) | 10% | — | HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+11 | 6/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors. | |
| Modificada | Media (4.3) | 0.96% | — | Cisco Video Surveillance Operations Manager | 14/6/2013 | 16/6/2026 | Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490. | |
| Modificada | Media (6.5) | 7.0% | 💥 Exploit | Qnap Viostor Network Video RecorderQnap Surveillance Station PROQnap NAS | 7/6/2013 | 16/6/2026 | cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string. | |
| Modificada | Media (5) | 1.3% | — | Qnap Viostor Network Video RecorderQnap Surveillance Station PROQnap NAS | 7/6/2013 | 16/6/2026 | QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors. | |
| Modificada | Media (6.8) | 1.5% | — | HP Procurve Switch SoftwareHP Procurve Switch 1700-24HP Procurve Switch 1700-8 | 28/3/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability on HP ProCurve 1700-8 (aka J9079A) switches with software before VA.02.09 and 1700-24 (aka J9080A) switches with software before VB.02.09 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Baja (2.6) | 0.90% | — | Limesurvey | 12/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters. | |
| Modificada | Media (4.3) | 1.2% | — | Limesurvey | 19/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.5) | 1.0% | — | Limesurvey | 19/9/2012 | 16/6/2026 | SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Limesurvey | 15/9/2012 | 16/6/2026 | SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php. | |
| Modificada | Baja (3.7) | 1.2% | — | HP Procurve Switch 5400zlHP Procurve Switch 5400zl Management ModuleHP Procurve Switch 5406-44g-poe+-4sfpzlHP Procurve Switch 5406-48gzl+10 | 12/4/2012 | 16/6/2026 | HP ProCurve 5400 zl switches with certain serial numbers include a compact flash card that contains an unspecified virus, which might allow user-assisted remote attackers to execute arbitrary code on a PC by leveraging manual transfer of this card. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Sellatsite Smart ASP Survey | 2/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter. | |
| Modificada | Alta (7.8) | 1.2% | — | Cisco Video Surveillance 2421Cisco Video Surveillance 2500Cisco Video Surveillance SoftwareCisco Video Surveillance 2600 | 27/10/2011 | 16/6/2026 | Cisco Video Surveillance 2421 and 2500 series cameras with software 1.1.x and 2.x before 2.4.0 and Video Surveillance 2600 series cameras with software before 4.2.0-13 allow remote attackers to cause a denial of service (device reload) by sending crafted RTSP packets over TCP, aka Bug IDs CSCtj96312, CSCtj39462, and… | |
| Modificada | Media (5) | 1.3% | — | Limesurvey | 23/9/2011 | 16/6/2026 | LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/statistics.php and certain other files. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Geovision Digital Surveillance System | 12/9/2011 | 16/6/2026 | Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request. | |
| Modificada | Alta (9.3) | 45% | 💥 Exploit | Visiwave Site Survey | 8/6/2011 | 16/6/2026 | VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference. | |
| Modificada | Media (4.3) | 1.9% | — | Fubra Wp-survey-and-quiz-tool | 30/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. |