Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

481 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.3)1.9%—HP Procurve Access Point SoftwareHP Procurve M110 Access PointHP Procurve Miltope Dual Radio Access PointHP Procurve Msm310-r Access Point+1418/10/201016/6/2026
Unspecified vulnerability on HP ProCurve Access Points, Access Controllers, and Mobility Controllers with software 5.1.x through 5.1.9, 5.2.x through 5.2.7, 5.3.x through 5.3.5, and 5.4.x through 5.4.0 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (6.1)0.89%—HP Procurve Switch SoftwareHP Procurve Switch 2610HP Procurve Switch 2610-24HP Procurve Switch 2610-24-pwr+39/8/201016/6/2026
Unspecified vulnerability on the HP ProCurve 2610 switch before R.11.22, when DHCP is enabled, allows remote attackers to cause a denial of service via unknown vectors.
ModificadaAlta (8.3)1.2%—HP Procurve Switch SoftwareHP Procurve Switch 2626HP Procurve Switch 2626-pwrHP Procurve Switch 2650+19/8/201016/6/2026
Unspecified vulnerability on the HP ProCurve 2626 and 2650 switches before H.10.80 allows remote attackers to obtain sensitive information, modify data, and cause a denial of service via unknown vectors.
ModificadaMedia (6.1)0.89%—HP Procurve Switch SoftwareHP Procurve Switch 2610HP Procurve Switch 2610-24HP Procurve Switch 2610-24-pwr+39/8/201016/6/2026
Unspecified vulnerability in the In-band Agent on the HP ProCurve 2610 switch before R.11.30 allows remote attackers to cause a denial of service via unknown vectors.
ModificadaMedia (6.1)0.98%—HP Procurve Switch SoftwareHP Procurve Switch 1800-24gHP Procurve Switch 1800-8g9/8/201016/6/2026
Unspecified vulnerability on the HP ProCurve 1800-24G switch with software PB.03.02 and earlier, and the ProCurve 1800-8G switch with software PA.03.02 and earlier, when SNMP is enabled, allows remote attackers to obtain sensitive information via unknown vectors.
ModificadaAlta (7.5)18%💥 ExploitTamlyncreative COM Bfsurvey ProfreeTamlyncreative COM Bfsurvey PROTamlyncreative COM Bfsurvey Basic9/6/201016/6/2026
Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)1.0%💥 ExploitTamlyncreative COM Bfsurvey ProfreeTamlyncreative COM Bfsurvey PROTamlyncreative COM Bfsurvey Basic9/6/201016/6/2026
SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these…
ModificadaAlta (7.5)2.4%💥 ExploitTamlyncreative COM Bfsurvey Profree18/1/201016/6/2026
SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage…
ModificadaMedia (6.8)0.28%—HP Procurve Identity Driven Manager29/9/200916/6/2026
Unspecified vulnerability in HP ProCurve Identity Driven Manager (IDM) A.02.x through A.02.03 and A.03.x through A.03.00, on Windows Server 2003 with IAS and Windows Server 2008 with NPS, allows local users to gain privileges via unknown vectors.
ModificadaAlta (7.5)0.96%💥 ExploitFocusdev COM Surveymanager23/9/200916/6/2026
SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.
ModificadaMedia (4.3)2.8%💥 ExploitCurveriderhq Elgg10/9/200916/6/2026
Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.99%💥 ExploitSellatsite.com Smart ASP Survey14/8/200916/6/2026
SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaAlta (7.8)3.2%—HP Procurve Threat Management Services ZL Module14/7/200916/6/2026
Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service by triggering a stop or crash in httpd, aka PR_18770, a different vulnerability than CVE-2009-1423 and CVE-2009-1424.
ModificadaAlta (7.8)2.5%—HP Procurve Threat Management Services ZL Module14/7/200916/6/2026
Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39412, a different vulnerability than CVE-2009-1423 and CVE-2009-1425.
ModificadaAlta (7.8)2.5%—HP Procurve Threat Management Services ZL Module14/7/200916/6/2026
Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39898, a different vulnerability than CVE-2009-1424 and CVE-2009-1425.
ModificadaAlta (10)5.1%💥 ExploitHP Procurve Threat Management Services ZL Module14/7/200916/6/2026
Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to gain privileges via unknown vectors, aka PR_41209.
ModificadaMedia (6.8)1.1%—Cisco Video Surveillance 2500 Series IP Camera25/6/200916/6/2026
The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allows remote attackers to read arbitrary files via a (1) http or (2) https request, related to the (a) SD Camera Web Server and the (b) Wireless Camera HTTP Server, aka Bug IDs CSCsu05515 and CSCsr96497.
ModificadaAlta (7.8)1.6%—Cisco Video Surveillance Stream Manager25/6/200916/6/2026
The Cisco Video Surveillance Stream Manager firmware before 5.3, as used on Cisco Video Surveillance Services Platforms and Video Surveillance Integrated Services Platforms, allows remote attackers to cause a denial of service (reboot) via a malformed payload in a UDP packet to port 37000, related to the xvcrman…
ModificadaAlta (7.5)1.8%—Limesurvey11/5/200916/6/2026
Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/.
ModificadaMedia (5)2.4%—HP Procurve Manager15/4/200916/6/2026
Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information from the ProCurve Manager server via unknown attack vectors.
ModificadaAlta (7.5)0.97%💥 ExploitTurnkeyforms Business Survey PRO2/3/200916/6/2026
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.1%—Typo3 Simplesurvey22/10/200816/6/2026
SQL injection vulnerability in the Simple survey (simplesurvey) 1.7.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.5%💥 ExploitJandus Technologies Smart Survey11/9/200816/6/2026
Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitPreproject PRE Survey Poll25/7/200816/6/2026
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaAlta (9.3)1.3%—Limesurvey6/6/200816/6/2026
Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.