Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.1% | — | Redhat Network SatelliteRedhat SatelliteRedhat Satellite With Embedded OracleSuse Manager+1 | 18/11/2013 | 16/6/2026 | Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts. | |
| Modificada | Media (4.3) | 2.8% | — | Scott Reynen Node Embed | 27/6/2012 | 16/6/2026 | The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0 for Drupal does not properly check permissions, which allows remote attackers to bypass intended access restrictions and read node titles. | |
| Modificada | Baja (2.1) | 0.48% | — | Oracle JREOracle JDKRedhat Icedtea6Redhat Satellite With Embedded Oracle+13 | 16/6/2012 | 16/6/2026 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux. | |
| Modificada | Media (5) | 2.3% | — | Kylegilman Video Embed & Thumbnail Generator | 19/3/2012 | 16/6/2026 | The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors. | |
| Modificada | Alta (7.5) | 3.4% | — | Kylegilman Video Embed & Thumbnail Generator | 19/3/2012 | 16/6/2026 | kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Oracle JDKOracle JRECanonical Ubuntu LinuxRedhat Satellite With Embedded Oracle+2 | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Ahmattox Processing Embed Plugin | 1/3/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Jovelstefan Embedded-video | 22/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in lembedded-video.php in the Embedded Video plugin 4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the content parameter to wp-admin/post.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joshprakash COM Jembed | 23/3/2010 | 16/6/2026 | SQL injection vulnerability in the jEmbed-Embed Anything (com_jembed) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a summary action to index.php. | |
| Modificada | Alta (9.3) | 18% | — | Microsoft Windows Embedded Compact | 12/5/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted (1) JPEG and (2) GIF images. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Checkpoint Vpn-1 UTM Edge W Embedded NGX | 8/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter. | |
| Modificada | Alta (10) | 3.3% | — | SUN Embedded Lights OUT Manager | 30/10/2007 | 16/6/2026 | Unspecified vulnerability in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) on x86 before firmware 2.70 allows remote attackers to execute arbitrary commands as root on the Service Processor (SP) via unspecified vectors, a different vulnerability than CVE-2007-5170. | |
| Modificada | Media (5) | 1.5% | — | SUN Embedded Lights OUT Manager | 1/10/2007 | 16/6/2026 | Unspecified vulnerability in the embedded service processor (SP) before 3.09 in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) allows remote attackers to send arbitrary network traffic and use ELOM as a spam proxy. | |
| Modificada | Media (5) | 1.6% | — | SUN Java Embedding Plugin | 30/5/2007 | 16/6/2026 | Java Embedding Plugin 0.9.6.1 allows remote attackers to cause a denial of service (browser crash) via a Thread subclass that calls super.run from its run method. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | Bsalsa Embeddedwb WEB Browser | 2/3/2007 | 16/6/2026 | Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (10) | 31% | — | Broadcom Widcomm BluetoothMicrosoft Windows Embedded CompactMicrosoft Windows Mobile | 31/12/2006 | 16/6/2026 | Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.7 on Windows, Widcomm Bluetooth Communication Software 1.4.1.03 on Windows, and the Bluetooth implementation in Windows Mobile or Windows… | |
| Modificada | Alta (7.5) | 4.4% | — | KDE KonquerorKDE Konqueror Embedded | 15/4/2004 | 16/6/2026 | Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application… | |
| Modificada | Media (5) | 2.9% | — | KDE KonquerorKDE Konqueror EmbeddedRedhat Analog Real-time SynthesizerRedhat Kdebase+4 | 27/8/2003 | 16/6/2026 | KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites. | |
| Modificada | Alta (7.5) | 2.1% | — | Apple SafariKDE Konqueror EmbeddedKDERedhat Linux+2 | 16/6/2003 | 16/6/2026 | Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack. | |
| Modificada | Media (5) | 0.77% | — | Apple SafariKDE Konqueror Embedded | 9/6/2003 | 16/6/2026 | Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates. | |
| Modificada | Alta (7.5) | 2.5% | — | Beck IPC Gmbh IPC AT Chip Embedded-webserver | 24/5/2001 | 16/6/2026 | The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 1.7% | — | Beck IPC Gmbh IPC AT Chip Embedded-webserver | 24/5/2001 | 16/6/2026 | Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to read arbitrary files via a webserver root directory set to system root. | |
| Modificada | Media (5) | 3.2% | — | Beck IPC Gmbh IPC AT Chip Embedded-webserver | 24/5/2001 | 16/6/2026 | The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program. | |
| Modificada | Media (5) | 1.6% | — | Beck IPC Gmbh IPC AT Chip Embedded-webserver | 21/5/2001 | 16/6/2026 | Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Microsoft Windows Embedded Compact | 1/1/2001 | 16/6/2026 | WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. |