Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.7% | — | Assist Project Assist PluginDatabox Project Databox PluginUserbox Project Userbox Plugin | 14/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Intel Quickassist Technology Engine | 7/3/2017 | 17/6/2026 | The RSA-CRT implementation in the Intel QuickAssist Technology (QAT) Engine for OpenSSL versions prior to 0.5.19 may allow remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack. | |
| Modificada | Crítica (9.8) | 5.9% | — | HP Support Assistant | 19/3/2016 | 17/6/2026 | HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors. | |
| Modificada | Media (6.1) | 1.6% | — | Greenbone Security AssistantGreenbone OSFedoraproject Fedora | 26/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a get_aggregate command to omp. | |
| Modificada | Media (5.4) | 0.27% | — | GOO Health Assistance Service | 21/10/2014 | 17/6/2026 | The Health assistance service (aka net.nttcloud.ft.karada) application 2.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Carrierenterprise Carrier Enterprise Hvac Assist | 20/10/2014 | 17/6/2026 | The Carrier Enterprise HVAC Assist (aka com.es.CE) application 4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mitsubishicars Mitsubishi Road Assist | 20/10/2014 | 17/6/2026 | The Mitsubishi Road Assist (aka com.agero.mitsubishi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Gemaire's Hvac Assist | 28/9/2014 | 17/6/2026 | The GEMAIRE's HVAC Assist (aka com.es.Gemaire) application 5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Infinitiusa Infiniti Roadside Assistance | 27/9/2014 | 17/6/2026 | The Infiniti Roadside Assistance (aka com.ccas.rsa.common.infiniti) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Skydrive Assistant Project Skydrive Assistant | 22/9/2014 | 17/6/2026 | The SkyDrive Assistant (aka com.dhh.sky) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Wargaming World OF Tanks Assistant | 9/9/2014 | 17/6/2026 | The World of Tanks Assistant (aka ru.worldoftanks.mobile) application 1.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Registeredassistant Project Registeredassistant | 9/9/2014 | 17/6/2026 | The RegisteredAssistant (aka Icr.RegisteredAssistant) application 0.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 2.1% | — | Cisco Telepresence VX Clinical Assistant | 8/11/2013 | 16/6/2026 | The WIL-A module in Cisco TelePresence VX Clinical Assistant 1.2 before 1.21 changes the admin password to an empty password upon a reboot, which makes it easier for remote attackers to obtain access via the administrative interface, aka Bug ID CSCuj17238. | |
| Modificada | Media (6.8) | 1.1% | — | Greenbone Security Assistant | 28/1/2011 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Greenbone Security Assistant (GSA) before 2.0+rc3 allows remote attackers to hijack the authentication of users for requests that send email via an OMP request to OpenVAS Manager. NOTE: this issue can be leveraged to bypass authentication requirements for exploiting… | |
| Modificada | Media (4.3) | 1.0% | — | Webassist Powerstore | 16/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Products_Results.php in PowerStore 3.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_WADAProducts parameter. | |
| Modificada | Alta (9.3) | 5.0% | — | Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance | 12/5/2010 | 16/6/2026 | The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when downloaded from a server operated by Telefonica or possibly other companies, contains an incorrect DNS whitelist that includes the DNS hostnames of… | |
| Modificada | Alta (9.3) | 5.2% | — | Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance | 12/5/2010 | 16/6/2026 | The SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to bypass intended restrictions on ActiveX execution via "instantiation/free attacks." | |
| Modificada | Alta (9.3) | 3.2% | — | Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance | 12/5/2010 | 16/6/2026 | The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance relies on a list of server domain names to restrict execution of ActiveX controls, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a… | |
| Modificada | Media (5.1) | 2.5% | — | Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance | 12/5/2010 | 16/6/2026 | The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields. | |
| Modificada | Alta (7.6) | 5.7% | — | Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance | 12/5/2010 | 16/6/2026 | Buffer overflow in the RunCmd method in the SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to execute arbitrary code via vectors involving "CreateProcess params." NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (9.3) | 2.3% | — | Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance | 12/5/2010 | 16/6/2026 | The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance does not properly restrict access to the HTTPDownloadFile, HTTPGetFile, Install, and RunCmd methods, which allows remote attackers to execute arbitrary programs via a URL in the url argument to (1)… | |
| Modificada | Media (4.3) | 1.5% | — | Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance | 12/5/2010 | 16/6/2026 | The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory, via a call to the GetUserName method. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Consona Live AssistanceConsona Dynamic AgentConsona Subscriber Assistance | 12/5/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HTML via crafted input to ASP pages, as demonstrated using the backurl parameter to sdccommon/verify/asp/n6plugindestructor.asp. | |
| Modificada | Media (5) | 1.3% | — | Unleashedmind IMG Assist | 4/1/2010 | 16/6/2026 | The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly enforce privilege requirements for unspecified pages, which allows remote attackers to read the (1) title or (2) body… | |
| Modificada | Baja (2.1) | 0.86% | — | Unleashedmind IMG Assist | 4/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, allows remote authenticated users, with image-node creation privileges, to inject arbitrary… |