Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 4.6% | — | Openvpn Access Server | 26/5/2017 | 17/6/2026 | CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters in the PATH_INFO to __session_start__/. | |
| Modificada | Crítica (9.8) | 7.1% | — | Dell Sonicwall Secure Remote Access Server | 22/2/2017 | 17/6/2026 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application… | |
| Modificada | Crítica (9.8) | 12% | — | Dell Sonicwall Secure Remote Access Server | 22/2/2017 | 17/6/2026 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server's internal… | |
| Modificada | Crítica (9.8) | 23% | — | Dell Sonicwall Secure Remote Access Server | 22/2/2017 | 17/6/2026 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system.… | |
| Modificada | Media (6.5) | 1.4% | — | Osisoft PI SQL Data Access Server 2016 | 19/6/2016 | 17/6/2026 | OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and data loss) via a message. | |
| Modificada | Media (6.8) | 3.5% | — | MageiaDebian LinuxOpensuseOpenvpn+2 | 3/12/2014 | 17/6/2026 | OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet. | |
| Modificada | Media (6.8) | 0.88% | — | Openvpn Access Server | 26/11/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) disconnecting established VPN sessions, (2) connect to arbitrary VPN servers, or (3)… | |
| Modificada | Media (6.8) | 0.97% | — | Openvpn Access Server | 13/5/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users. | |
| Modificada | Baja (2.6) | 2.8% | — | OpenvpnOpenvpn Access ServerOpensuse | 18/11/2013 | 16/6/2026 | The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Media (5.5) | 0.24% | — | Klinzmann Application Access Server | 14/5/2009 | 16/6/2026 | Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file. | |
| Modificada | Alta (7.5) | 1.4% | — | Klinzmann Application Access Server | 14/5/2009 | 16/6/2026 | Application Access Server (A-A-S) 2.0.48 has "wildbat" as its default password for the admin account, which makes it easier for remote attackers to obtain access. | |
| Modificada | Media (6.8) | 0.73% | — | Klinzmann Application Access Server | 14/5/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary programs via a command job, (2) stop services via a setservice job, or (3) terminate… | |
| Modificada | Media (4) | 1.3% | — | OpenvpnOpenvpn Access Server | 5/5/2006 | 16/6/2026 | OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service. | |
| Modificada | Alta (9) | 3.1% | — | OpenvpnOpenvpn Access Server | 6/4/2006 | 16/6/2026 | OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable. | |
| Modificada | Media (5) | 2.5% | — | OpenvpnOpenvpn Access Server | 2/11/2005 | 16/6/2026 | OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler. | |
| Modificada | Alta (7.5) | 3.5% | — | OpenvpnOpenvpn Access Server | 1/11/2005 | 16/6/2026 | Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option. | |
| Modificada | Baja (2.1) | 0.54% | — | A-a-s Application Access Server | 31/12/2004 | 16/6/2026 | Application Access Server (A-A-S) 1.0.37 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long file request. |