Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
456 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.44% | — | Openfabrics Ibutils | 15/4/2014 | 16/6/2026 | Untrusted search path vulnerability in a certain Red Hat build script for the ibmssh executable in ibutils packages before ibutils-1.5.7-2.el6 in Red Hat Enterprise Linux (RHEL) 6 and ibutils-1.2-11.2.el5 in Red Hat Enterprise Linux (RHEL) 5 allows local users to gain privileges via a Trojan Horse program in… | |
| Modificada | Media (6.3) | 0.50% | — | Redhat Enterprise LinuxOpenfabrics Ibutils | 23/11/2013 | 16/6/2026 | OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/. | |
| Modificada | Media (4.6) | 0.34% | — | Cisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric Interconnect | 30/8/2013 | 16/6/2026 | Memory leak in the CLI component on Cisco Unified Computing System (UCS) 6100 Fabric Interconnect devices, in certain situations that lack a SPAN session, allows local users to cause a denial of service (memory consumption and device reset) via a (1) "show monitor session all" or (2) "show monitor session" command,… | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Fabricio Zuardi Xspf Player Plugin | 10/5/2013 | 16/6/2026 | SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC), aka Bug ID CSCts53746. | |
| Modificada | Alta (9.3) | 1.8% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows remote attackers to obtain sensitive information by reading a (1) technical-support bundle file or (2) on-device configuration backup, aka Bug ID CSCtq86543. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | The management API in the XML API management service in the Manager component in Cisco Unified Computing System (UCS) 1.x before 1.2(1b) allows remote attackers to cause a denial of service (service outage) via a malformed request, aka Bug ID CSCtg48206. | |
| Modificada | Alta (10) | 3.6% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+1 | 25/4/2013 | 16/6/2026 | Buffer overflow in the Intelligent Platform Management Interface (IPMI) functionality in the Manager component in Cisco Unified Computing System (UCS) 1.0 and 1.1 before 1.1(1j) and 1.2 before 1.2(1b) allows remote attackers to execute arbitrary code via malformed data in a UDP packet, aka Bug ID CSCtd32371. | |
| Modificada | Alta (9.3) | 3.5% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) allows remote attackers to bypass LDAP authentication via a malformed request, aka Bug ID CSCtc91207. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Nx-osCisco Nexus 5548pCisco Nexus 5548upCisco Nexus 5596up+8 | 25/4/2013 | 16/6/2026 | Cisco NX-OS on Nexus 5500 devices 4.x and 5.x before 5.0(3)N2(2), Nexus 3000 devices 5.x before 5.0(3)U3(2), and Unified Computing System (UCS) 6200 devices before 2.0(1w) allows remote attackers to cause a denial of service (device reload) by sending a jumbo packet to the management interface, aka Bug IDs CSCtx17544,… | |
| Modificada | Alta (8.3) | 1.4% | — | Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+23 | 25/4/2013 | 16/6/2026 | Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V… | |
| Modificada | Media (4.3) | 1.8% | — | Sourcefabric Newscoop | 22/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) language parameter to application/modules/admin/controllers/LanguagesController.php or (2) user parameter to… | |
| Modificada | Baja (3.6) | 0.36% | — | Openfabrics Ibacm | 22/10/2012 | 16/6/2026 | ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file. | |
| Modificada | Media (5) | 2.8% | — | Openfabrics Ibacm | 22/10/2012 | 16/6/2026 | ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a crafted join response. | |
| Modificada | Media (5.8) | 2.1% | — | Openfabrics Librdmacm | 22/10/2012 | 16/6/2026 | librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a malicious ib_acm service. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the f_user_name parameter. | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject arbitrary web script or HTML via the (1) Back parameter to admin/ad.php, or the (2) token or (3) f_email parameter to admin/password_check_token.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbitrary SQL commands via the f_country_code parameter. | |
| Modificada | Media (6.8) | 5.6% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) include/phorum_load.php, (2) conf/install_conf.php, or (3)… | |
| Modificada | Media (5) | 1.2% | — | Tibco Activematrix BPMTibco Activematrix Businessworks Service EngineTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 13/3/2012 | 16/6/2026 | The server in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote attackers to discover credentials via unspecified vectors. | |
| Modificada | Media (4.3) | 0.92% | — | Tibco Silver Fabric Activematrix Service Grid DistributionTibco Activematrix Service GridTibco Activematrix Service BUSTibco Activematrix Businessworks Service Engine+1 | 13/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote attackers to inject arbitrary web script or… | |
| Modificada | Media (5) | 1.4% | — | Tibco Activematrix Service BUSTibco Activematrix Service GridTibco Activematrix Businessworks Service EngineTibco Silver Fabric Activematrix Service Grid Distribution+3 | 13/3/2012 | 16/6/2026 | TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before… | |
| Modificada | Media (4.3) | 0.85% | — | Sourcefabric Campsite | 1/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the f_search_keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Baja (2.1) | 0.34% | — | Openfabrics Enterprise Distribution | 19/9/2011 | 16/6/2026 | ulp/sdp/sdp_proc.c in the ib_sdp module (aka ib_sdp.ko) in the ofa_kernel package in the InfiniBand driver implementation in OpenFabrics Enterprise Distribution (OFED) before 1.5.3 does not properly handle certain non-array variables, which allows local users to cause a denial of service (stack memory corruption and… | |
| Modificada | Media (4.4) | 0.33% | — | Fabfile Fabric | 27/7/2011 | 16/6/2026 | Fabric before 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on (1) a /tmp/fab.*.tar file or (2) certain other files in the top level of /tmp/. |