Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
474 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Mindtouch Dekiwiki | 25/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in MindTouch DekiWiki before 8.05.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Wonderware IntouchWonderware Suitelink | 6/5/2008 | 16/6/2026 | The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port… | |
| Modificada | Alta (8.8) | 3.0% | — | Wonderware Intouch | 20/11/2007 | 16/6/2026 | Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Thomson Speedtouch | 15/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Alcatel Speedtouch 7G RouterBT Home HUB | 12/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 3.8% | — | Alcatel Speedtouch 7G RouterBT Home HUB | 12/10/2007 | 16/6/2026 | The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the end of the PATH_INFO to cgi/b, aka "double-slash auth bypass." NOTE: remote… | |
| Modificada | Media (4.3) | 0.61% | — | Alcatel Speedtouch 7G RouterBT Home HUB | 12/10/2007 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to perform actions as administrators via unspecified POST requests, as demonstrated by enabling an inbound remote-assistance HTTPS session on… | |
| Modificada | Media (4.3) | 1.1% | — | Mindtouch Dekiwiki | 12/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in skins/ace/popup-notopic.php in MindTouch OpenGarden DekiWiki before Gooseberry++ allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Touch Control Activex Control | 21/7/2006 | 16/6/2026 | The Touch Control ActiveX control 2.0.0.55 allows remote attackers to read and possibly execute arbitrary files via a "file///" URI in the sPath parameter to the Execute function. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Thomson Speedtouch | 1/3/2006 | 16/6/2026 | Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Thomson Speedtouch | 1/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Intouch | 5/1/2006 | 16/6/2026 | SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter. | |
| Modificada | Media (4.6) | 0.69% | 💥 Exploit | Info Touch Surfnet | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command. | |
| Modificada | Media (4.6) | 0.40% | — | Info Touch Surfnet | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts. | |
| Modificada | Baja (2.1) | 0.32% | — | Info Touch Surfnet KioskAI | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI. | |
| Modificada | Alta (7.2) | 0.43% | — | Mandrakesoft Mandrake Multi Network FirewallSpeedtouch USB DriverGentoo LinuxMandrakesoft Mandrake Linux+1 | 23/12/2004 | 16/6/2026 | Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Thomson Speedtouch | 5/8/2004 | 16/6/2026 | Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. | |
| Modificada | Media (4.6) | 0.37% | — | Logitech Cordless Freedom Itouch KeyboardLogitech Cordless Itouch KeyboardLogitech Itouch Keyboard | 31/12/2002 | 16/6/2026 | Logitech iTouch keyboards allows attackers with physical access to the system to bypass the screen locking function and execute user-defined commands that have been assigned to a button. | |
| Modificada | Media (5) | 1.9% | — | Alcatel Speed Touch Home | 25/3/2002 | 16/6/2026 | Alcatel Speed Touch Home ADSL Modem allows remote attackers to cause a denial of service (reboot) via a network scan with unusual packets, such as nmap with OS detection. | |
| Modificada | Alta (7.5) | 2.4% | — | Alcatel Adsl Modem 1000Alcatel Speed Touch Adsl Modem | 31/12/2001 | 16/6/2026 | Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication. | |
| Modificada | Alta (7.5) | 1.7% | — | Logitech Cordless FreedomLogitech Cordless Freedom NavigatorLogitech Cordless Freedom PROLogitech Cordless Itouch Keyboard | 18/10/2001 | 16/6/2026 | A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack. | |
| Modificada | Alta (7.5) | 3.5% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 2.0% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations. | |
| Modificada | Alta (7.5) | 3.7% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login. |