Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 4.7% | — | GE Infinia Hawkeye 4 Firmware | 20/3/2018 | 17/6/2026 | GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices. | |
| Modificada | Alta (8.8) | 4.2% | 💥 Exploit | Watchguard Hawkeye G | 23/10/2017 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to interface/rest/accounts/json; turn off the (2) Url matching, (3) DNS Inject, or (4) IP… | |
| Modificada | Alta (7.5) | 3.4% | — | Hawk Project Hawk | 13/4/2016 | 17/6/2026 | Hawk before 3.1.3 and 4.x before 4.1.1 allow remote attackers to cause a denial of service (CPU consumption or partial outage) via a long (1) header or (2) URI that is matched against an improper regular expression. | |
| Modificada | Media (5.4) | 0.27% | — | Unitedhawknation United Hawk Nation | 21/10/2014 | 17/6/2026 | The United Hawk Nation (aka com.united12thman) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 4.8% | — | Tibco HawkTibco Iprocess EngineTibco Mainframe Service TrackerTibco Runtime Agent | 13/8/2008 | 16/6/2026 | Multiple buffer overflows in TIBCO Hawk (1) AMI C library (libtibhawkami) and (2) Hawk HMA (tibhawkhma), as used in TIBCO Hawk before 4.8.1; Runtime Agent (TRA) before 5.6.0; iProcess Engine 10.3.0 through 10.6.2 and 11.0.0; and Mainframe Service Tracker before 1.1.0 might allow remote attackers to execute arbitrary… | |
| Modificada | Alta (9.3) | 4.8% | — | Tibco Adapter Files Z OSTibco HawkTibco Iprocess EngineTibco Rendezvous+4 | 11/4/2008 | 16/6/2026 | Multiple buffer overflows in TIBCO Software Rendezvous before 8.1.0, as used in multiple TIBCO products, allow remote attackers to execute arbitrary code via a crafted message. | |
| Modificada | Media (4.3) | 44% | 💥 Exploit | Apache Myfaces Tomahawk | 18/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client. | |
| Modificada | Media (5) | 1.2% | — | Hawking Technology Wr254-ca Wireless Router | 15/11/2006 | 16/6/2026 | Hawking Technology wireless router WR254-CA uses a hardcoded IP address among the set of DNS server IP addresses, which could allow remote attackers to cause a denial of service or hijack the router by attacking or spoofing the server at the hardcoded address. NOTE: it could be argued that this issue reflects an… | |
| Modificada | Media (6.8) | 0.47% | — | Tibco HawkTibco Hawk Monitoring AgentTibco Runtime Agent | 5/6/2006 | 16/6/2026 | Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma. | |
| Modificada | Alta (7.5) | 6.0% | — | Tibco HawkTibco RendezvousTibco Runtime Agent | 5/6/2006 | 16/6/2026 | Buffer overflow in TIBCO Rendezvous before 7.5.1, TIBCO Runtime Agent (TRA) before 5.4, and Hawk before 4.6.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the HTTP administrative interface. | |
| Modificada | Media (4.3) | 1.3% | — | Xhawk.net Discussion | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0 beta2 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag. | |
| Modificada | Alta (7.5) | 1.3% | — | Xhawk.net Discussion | 19/3/2006 | 16/6/2026 | SQL injection vulnerability in discussion.class.php in xhawk.net discussion 2.0 beta2 allows remote attackers to execute arbitrary SQL commands via the view parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Hawking Technology Har11a DSL Router | 26/10/2004 | 16/6/2026 | The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections. | |
| Modificada | Alta (7.5) | 6.3% | — | Tomahawk Technologies Steelarrow | 11/4/2003 | 16/6/2026 | Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding… | |
| Modificada | Alta (7.5) | 1.3% | — | Logisense DNS Manager SystemLogisense Hawk-i | 4/10/2002 | 16/6/2026 | SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field. | |
| Modificada | Alta (7.2) | 0.94% | 💥 Exploit | SAM Hawker Wmcdplay | 10/3/2000 | 16/6/2026 | Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter. | |
| Modificada | Media (5) | 1.7% | — | Data General DG UXNCR Mp-rasSGI IrixIBM AIX+6 | 24/4/1996 | 16/6/2026 | Delete or create a file via rpc.statd, due to invalid information. |