Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

453 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)1.3%—IBM Infosphere Import Export ManagerIBM Infosphere Information ServerIBM Infosphere Information Server Metabrokers & Bridges31/1/201316/6/2026
Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
ModificadaAlta (7.5)1.1%💥 ExploitPhpbridges DEV Team Phpbridges31/1/201316/6/2026
SQL injection vulnerability in members.php in PHPBridges allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.8)1.9%—Cisco IOSCisco Aironet 1040Cisco Aironet 1140Cisco Aironet 1260+156/8/201216/6/2026
Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.
ModificadaMedia (4)38%💥 ExploitMicrosoft Forms ServerMicrosoft GrooveMicrosoft Groove Data Bridge ServerMicrosoft Groove Management Server+615/9/201116/6/2026
Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint…
ModificadaAlta (10)3.7%—Sybase Onebridge Mobile Data Suite9/6/201116/6/2026
Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and 5.6 allows remote attackers to execute arbitrary code via format string specifiers in unspecified string fields, related to authentication…
ModificadaAlta (7.5)0.97%💥 ExploitShape5 Bridge OF Hope Template9/6/201016/6/2026
SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.
ModificadaMedia (5)5.9%—Rockwellautomation Controllogix 1756-enbt/a Ethernet/ IP Bridge6/2/200916/6/2026
The web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to obtain "internal web page information" and "internal information about the module" via unspecified vectors. NOTE: this may overlap CVE-2002-1603.
ModificadaMedia (6.8)13%💥 PoCRockwellautomation Controllogix 1756-enbt/a Ethernet/ IP Bridge6/2/200916/6/2026
Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (4.3)2.9%—Rockwellautomation Controllogix 1756-enbt/a Ethernet/ IP Bridge6/2/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9)5.4%💥 ExploitCambridge Computer Corporation Vxftpsrv6/10/200816/6/2026
Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (crash and hang) and possibly execute arbitrary code via a long CWD request.
ModificadaAlta (7.2)0.68%—Adobe Bridge11/4/200716/6/2026
Unspecified vulnerability in the installer for Adobe Bridge 1.0.3 update for Apple OS X, when patching with desktop management tools, allows local users to gain privileges via unspecified vectors during installation of the update by a different user who has administrative privileges.
ModificadaMedia (5.4)0.94%—Intel Enterprise Southbridge 2 BMCIntel Enterprise Southbridge BMCIntel Server Board S5000palIntel Server Board S5000psl+51/2/200716/6/2026
Intel Enterprise Southbridge 2 Baseboard Management Controller (BMC), Intel Server Boards 5000XAL, S5000PAL, S5000PSL, S5000XVN, S5000VCL, S5000VSA, SC5400RA, and OEM Firmware for Intel Enterprise Southbridge Baseboard Management Controller before 20070119, when Intelligent Platform Management Interface (IPMI) is…
ModificadaCrítica (9.8)13%💥 ExploitEnigma Wordpress Bridge31/12/200616/6/2026
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. NOTE: CVE disputes this issue, since $boarddir is set to a fixed value
ModificadaAlta (10)5.1%💥 ExploitEnigma2 Coppermine Bridge31/12/200616/6/2026
PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter.
ModificadaAlta (7.5)3.1%—Cambridge Computer Corporation Vxweb22/9/200516/6/2026
Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
ModificadaAlta (7.5)3.8%—Cambridge Computer Corporation Vxtftpsrv22/9/200516/6/2026
Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument.
ModificadaAlta (7.5)3.8%—Cambridge Computer Corporation Vxftpsrv22/9/200516/6/2026
Buffer overflow in vxFtpSrv 0.9.7 allows remote attackers to execute arbitrary code via a long USER name.
ModificadaMedia (4.6)0.72%—University OF Cambridge Exim2/5/200516/6/2026
Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.
ModificadaAlta (7.2)2.6%💥 ExploitUniversity OF Cambridge Exim2/5/200516/6/2026
Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which…
ModificadaAlta (7.5)21%💥 ExploitUniversity OF Cambridge Exim7/7/200416/6/2026
Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.
ModificadaAlta (7.5)7.0%—University OF Cambridge Exim7/7/200416/6/2026
Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.
ModificadaAlta (7.5)5.7%—University OF Cambridge Exim20/10/200316/6/2026
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no…
ModificadaAlta (7.2)2.3%💥 ExploitUniversity OF Cambridge Exim23/12/200216/6/2026
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
ModificadaMedia (4.6)0.38%—University OF Cambridge Exim31/5/200216/6/2026
Exim 3.34 and earlier may allow local users to gain privileges via a buffer overflow in long -C (configuration file) and other command line arguments.
ModificadaAlta (7.5)6.4%—University OF Cambridge EximRedhat Linux19/12/200116/6/2026
Exim 3.22 and earlier, in some configurations, does not properly verify the local part of an address when redirecting the address to a pipe, which could allow remote attackers to execute arbitrary commands via shell metacharacters.
Orbitaley — Vulnerabilidades