Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

447 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—Actualscripts Actualanalyzer GoldActualscripts Actualanalyzer LiteActualscripts Actualanalyzer PROActualscripts Actualanalyzer Server3/6/200816/6/2026
Cross-site scripting (XSS) vulnerability in view.php in ActualScripts ActualAnalyzer Server 8.37 and earlier, ActualAnalyzer Gold 7.74 and earlier, ActualAnalyzer Pro 6.95 and earlier, and ActualAnalyzer Lite 2.78 and earlier allows remote attackers to inject arbitrary web script or HTML via the language parameter.
ModificadaAlta (7.5)6.3%💥 ExploitActualscripts Actualanalyzer Lite5/5/200816/6/2026
Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the style parameter.
ModificadaBaja (3.5)0.83%—Manageengine Firewall Analyzer14/4/200816/6/2026
Cross-site scripting (XSS) vulnerability in mindex.do in ManageEngine Firewall Analyzer 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the displayName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)0.84%—Manageengine Eventlog Analyzer28/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in searchAction.do in ManageEngine EventLog Analyzer 5 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Fixed in…
ModificadaAlta (7.5)1.4%—Adventnet Eventlog Analyzer21/11/200716/6/2026
AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" account without a password, which allows remote attackers to gain privileges and modify logs. Fixed in EventLog Analyzer Build 6000.
ModificadaMedia (6.8)3.7%💥 ExploitEiqnetworks Enterprise Security Analyzer29/10/200716/6/2026
Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arbitrary code via certain data on TCP port 10616 that results in a long argument to the SEARCHREPORT command, a different vector than CVE-2007-2059.
ModificadaMedia (4.3)4.1%💥 ExploitAdventnet Manageengine Netflow Analyzer6/7/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflow/jspui/appConfig.jsp, the (3) view parameter in (c)…
ModificadaBaja (2.6)5.8%💥 ExploitAdventnet Manageengine Netflow Analyzer6/7/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName, (3) displayName, and (4) selectedNode parameters to (c)…
ModificadaAlta (10)7.3%💥 ExploitEiqnetworks Enterprise Security Analyzer18/4/200716/6/2026
Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute arbitrary code via a long parameter to the (1) DELETESEARCHFOLDER, (2) DELTASK, (3) HMGR_CHECKHOSTSCSV, (4) TASKUPDATEDUSER, (5) VERIFYUSERKEY, or (6) VERIFYPWD command.
ModificadaMedia (4)1.2%—Manageengine Firewall Analyzer24/3/200716/6/2026
Unspecified vulnerability in ManageEngine Firewall Analyzer allows remote authenticated users to "access any common file" via a direct URL request.
ModificadaBaja (2.1)0.37%—Norman Sandbox Analyzer2/3/200716/6/2026
Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze.
ModificadaMedia (5)7.6%💥 ExploitEiqnetworks Enterprise Security Analyzer13/1/200716/6/2026
The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) &LOGPATH& (6) &FWADELTA& (7) &FWALOG& (8) &SETSYNCHRONOUS& (9) &SETPRGFILE&, or (10) &SETREPLYPORT& string to TCP…
ModificadaAlta (7.5)2.8%💥 ExploitPhpprintanalyzer16/8/200616/6/2026
PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ficStyle parameter.
ModificadaAlta (7.5)3.2%💥 ExploitThomas Pequet Phpprintanalyzer10/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. NOTE: this issue has been disputed by third party researchers, stating that the…
ModificadaAlta (10)74%💥 ExploitEiqnetworks Enterprise Security Analyzer27/7/200616/6/2026
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network Security Analyzer, and possibly other products, allow remote…
ModificadaAlta (7.5)13%💥 ExploitActualscripts Actualanalyzer21/4/200616/6/2026
PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.
ModificadaMedia (4.3)1.9%💥 ExploitAdventnet Manageengine Netflow Analyzer6/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.
ModificadaAlta (7.5)1.3%—MS Analysis Website Traffic Analyzer31/12/200416/6/2026
SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.
ModificadaMedia (4.3)1.3%—Nihuo Software WEB LOG Analyzer20/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
ModificadaMedia (5)3.2%—Microsoft Baseline Security Analyzer10/2/200416/6/2026
Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.
ModificadaMedia (5)16%—Microsoft Baseline Security Analyzer31/12/200216/6/2026
Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain sensitive information about the system via malicious active content such as ActiveX controls or Java.
ModificadaBaja (2.1)0.40%—Webtrends Enterprise SuiteWebtrends FOR FirewallsWebtrends LOG AnalyzerWebtrends Professional Suite+129/6/199916/6/2026
WebTrends software stores account names and passwords in a file which does not have restricted access permissions.