Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.27%—Solarwinds Kiwi Syslog Server25/10/202117/6/2026
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path:…
ModificadaMedia (5.4)13%—Nagios LOG Server30/7/202117/6/2026
Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page.
ModificadaMedia (5.4)77%—Nagios LOG Server30/7/202117/6/2026
Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.
ModificadaAlta (8.8)41%—Klogserver Klog Server26/1/202117/6/2026
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.
ModificadaMedia (6.1)16%—Nagios LOG Server20/1/202117/6/2026
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page.
ModificadaCrítica (9.8)88%—Klogserver Klog Server27/12/202017/6/2026
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
ModificadaMedia (5.4)14%—Nagios LOG Server30/7/202017/6/2026
A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
ModificadaMedia (6.1)1.6%—Nagios LOG Server3/9/201917/6/2026
Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.
ModificadaAlta (7.8)3.2%—Common Controls Replacement Project Browsedialog Server2/3/200716/6/2026
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder property value, different vectors than CVE-2007-0371.
ModificadaMedia (4.3)2.3%—Common Controls Replacement Project Browsedialog Server19/1/200716/6/2026
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.
ModificadaMedia (4.3)1.4%—Apple Weblog ServerApple MAC OS X19/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.