Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—GNU Exosip14/8/201917/6/2026
handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.
ModificadaAlta (8.1)1.0%—Extremenetworks Extremexos23/10/201717/6/2026
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values.
ModificadaMedia (6.7)0.37%—Extremenetworks Extremexos23/10/201717/6/2026
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.
ModificadaMedia (6.7)0.32%—Extremenetworks Extremexos23/10/201717/6/2026
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.
ModificadaMedia (6.7)0.27%—Extremenetworks Extremexos23/10/201717/6/2026
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.
ModificadaAlta (7.5)1.3%—Extremenetworks Extremexos23/10/201717/6/2026
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot.
ModificadaMedia (4.4)0.34%—Extremenetworks Extremexos23/10/201717/6/2026
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to read arbitrary files.
ModificadaMedia (5.4)1.2%—Extremenetworks Exos23/1/201417/6/2026
The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet…
ModificadaMedia (5)1.3%—Exoscripts Exophpdesk23/9/201116/6/2026
ExoPHPDesk 1.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by upgrades/upgrade9.php and certain other files.
ModificadaAlta (7.5)1.0%💥 ExploitExoscripts Exophpdesk7/8/200916/6/2026
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQL commands via the username (user parameter).
ModificadaAlta (7.5)5.3%💥 ExploitCdexos Cdex20/3/200916/6/2026
Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vorbis (.ogg) file.
ModificadaAlta (10)3.3%—Bsdi BSD OSConvexosConvex Spp-uxCray Unicos+319/10/199516/6/2026
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
Orbitaley — Vulnerabilidades