Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.27% | — | Solarwinds Kiwi Syslog Server | 25/10/2021 | 17/6/2026 | As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path:… | |
| Modificada | Media (5.4) | 13% | — | Nagios LOG Server | 30/7/2021 | 17/6/2026 | Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page. | |
| Modificada | Media (5.4) | 77% | — | Nagios LOG Server | 30/7/2021 | 17/6/2026 | Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page. | |
| Modificada | Alta (8.8) | 41% | — | Klogserver Klog Server | 26/1/2021 | 17/6/2026 | KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter. | |
| Modificada | Media (6.1) | 16% | — | Nagios LOG Server | 20/1/2021 | 17/6/2026 | Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page. | |
| Modificada | Crítica (9.8) | 88% | — | Klogserver Klog Server | 27/12/2020 | 17/6/2026 | KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter. | |
| Modificada | Media (5.4) | 14% | — | Nagios LOG Server | 30/7/2020 | 17/6/2026 | A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu. | |
| Modificada | Media (6.1) | 1.6% | — | Nagios LOG Server | 3/9/2019 | 17/6/2026 | Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page. | |
| Modificada | Alta (7.8) | 3.2% | — | Common Controls Replacement Project Browsedialog Server | 2/3/2007 | 16/6/2026 | A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder property value, different vectors than CVE-2007-0371. | |
| Modificada | Media (4.3) | 2.3% | — | Common Controls Replacement Project Browsedialog Server | 19/1/2007 | 16/6/2026 | A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value. | |
| Modificada | Media (4.3) | 1.4% | — | Apple Weblog ServerApple MAC OS X | 19/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. |