Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Sourcecodester Logistic HUB Parcel's Management System Project Sourcecodester Logistic HUB Parcel's Management System | 20/1/2022 | 17/6/2026 | An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php. | |
| Modificada | Alta (8.1) | 0.83% | — | Parc Project Parc | 8/8/2021 | 17/6/2026 | An issue was discovered in the parc crate through 2020-11-14 for Rust. LockWeak<T> has an unconditional implementation of Send without trait bounds on T. | |
| Modificada | Media (5.9) | 0.60% | — | Fujitsu Gp7000f FirmwareFujitsu Primepower FirmwareFujitsu GPS FirmwareFujitsu Sparc Enterprise M3000 Firmware+36 | 7/2/2020 | 17/6/2026 | The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions,… | |
| Modificada | Crítica (9.8) | 22% | — | Teclib-edition Gestionnaire Libre DE Parc Informatique | 27/3/2019 | 17/6/2026 | Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php. | |
| Modificada | Crítica (9.8) | 2.5% | — | Teclib-edition Gestionnaire Libre DE Parc Informatique | 27/3/2019 | 17/6/2026 | Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occurs in Auth::checkPassword() (inc/auth.class.php). | |
| Modificada | Alta (7.5) | 2.3% | — | Parceljs Parcel | 21/9/2018 | 17/6/2026 | An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1… | |
| Modificada | Media (4.4) | 0.36% | — | Oracle Sparc-sun System Firmware | 19/10/2017 | 17/6/2026 | Vulnerability in the SPARC M7, T7, S7 based Servers component of Oracle Sun Systems Products Suite (subcomponent: Firmware). The supported version that is affected is Prior to 9.7.6.b. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where SPARC M7, T7, S7 based Servers… | |
| Modificada | Media (6.5) | 2.7% | — | Linux-pamOracle Sparc-opl Service Processor | 24/8/2015 | 17/6/2026 | The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password. | |
| Modificada | Alta (7.5) | 74% | — | OpensslOracle Sparc-opl Service Processor | 12/6/2015 | 17/6/2026 | The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted length field in ASN1_TIME data, as demonstrated by an attack… | |
| Modificada | Baja (3.7) | 100% | — | OpensslCanonical Ubuntu LinuxHp-uxIBM Content Manager+21 | 21/5/2015 | 17/6/2026 | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a… | |
| Modificada | Baja (3.7) | 74% | — | Oracle Communications Application Session ControllerOracle Communications Policy ManagementOracle Http ServerOracle Integrated Lights OUT Manager Firmware+57 | 1/4/2015 | 17/6/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally… | |
| Modificada | Alta (7.5) | 1.6% | — | Parcimonie Project Parcimonie | 14/2/2014 | 17/6/2026 | parcimonie before 0.8.1, when using a large keyring, sleeps for the same amount of time between fetches, which allows attackers to correlate key fetches via unspecified vectors. | |
| Modificada | Media (6.9) | 0.41% | — | Oracle SUN System FirmwareOracle Sparc T4-1Oracle Sparc T4-1bOracle Sparc T4-4 | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in Oracle PARC Enterprise T4 Servers running Sun System Firmware before 8.3.0.b allows local users to affect confidentiality, integrity, and availability via vectors related to Sun System Firmware/Integrated Lights Out Manager (ILOM). | |
| Modificada | Media (4) | 0.27% | — | Oracle SUN System FirmwareOracle Sparc Enterprise M8000 ServerOracle Sparc Enterprise M9000 ServerOracle Sparc T3-1+8 | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in Oracle SPARC Enterprise T & M Series Servers running Sun System Firmware before 6.7.13 for SPARC T1, 7.4.6.c for SPARC T2, 8.3.0.b for SPARC T3 & T4, 9.0.0.d for SPARC T5 and 9.0.1.e for SPARC M5 allows local users to affect availability via unknown vectors related to Sun System… | |
| Modificada | Media (5) | 1.6% | — | Oracle XCPOracle Sparc Enterprise M3000 ServerOracle Sparc Enterprise M4000 ServerOracle Sparc Enterprise M5000 Server+2 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the SPARC Enterprise M Series Servers component in Oracle and Sun Systems Products Suite XCP 1114 and earlier allows remote attackers to affect availability via vectors related to XSCF Control Package (XCP). | |
| Modificada | Media (5.9) | 84% | — | Oracle Communications Application Session ControllerOracle Http ServerOracle Integrated Lights OUT Manager FirmwareFujitsu Sparc Enterprise M3000 Firmware+12 | 15/3/2013 | 16/6/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext. | |
| Modificada | Baja (2.1) | 0.36% | — | Oracle SUN Products Suite SysfwOracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Netra Sparc T4-1+9 | 17/10/2012 | 16/6/2026 | Unspecified vulnerability in the Integrated Lights Out Manager CLI in Oracle Sun Products Suite SysFW 8.2.0.a for SPARC and Netra SPARC T3 and T4-based servers, and other versions and servers, allows local users to affect confidentiality via unknown vectors. | |
| Modificada | Baja (3.7) | 0.34% | — | Oracle Sparc T-series Server FirmwareOracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Netra Sparc T4-1+10 | 17/7/2012 | 16/6/2026 | Unspecified vulnerability in Oracle SPARC T-Series Servers running System Firmware 8.2.0 and 8.1.4.e or earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Integrated Lights Out Manager. | |
| Modificada | Baja (2.6) | 2.1% | — | Oracle XCPOracle Sparc Enterprise M3000 ServerOracle Sparc Enterprise M4000 ServerOracle Sparc Enterprise M5000 Server+2 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in Oracle SPARC Enterprise M Series Servers XCP 1110 allows remote attackers to affect availability, related to XSCF Control Package (XCP). | |
| Modificada | Baja (2.1) | 0.40% | — | Oracle XCPOracle Sparc Enterprise M3000 ServerOracle Sparc Enterprise M4000 ServerOracle Sparc Enterprise M5000 Server+2 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in Oracle SPARC Enterprise M Series Servers XCP 1110 and earlier allows local users to affect confidentiality, related to XSCF Control Package (XCP). | |
| Modificada | Baja (2.1) | 0.40% | — | Oracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Sparc T3-1Oracle Sparc T3-1b+15 | 18/10/2011 | 16/6/2026 | Unspecified vulnerability in SysFW 8.0 on certain SPARC T3, Netra SPARC T3, Sun Fire, and Sun Blade based servers allows local users to affect confidentiality, related to Integrated Lights Out Manager CLI. | |
| Modificada | Alta (7.5) | 1.4% | — | Oracle SysfwOracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Sparc T3-1+8 | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in Oracle SysFW 8.1.0.a in various Oracle SPARC T3, Netra SPARC T3, Sun Fire, and Sun Blade servers allows remote attackers to affect confidentiality, integrity, and availability, related to Sun Integrated Lights Out Manager (ILOM). | |
| Modificada | Alta (7.5) | 1.4% | — | Oracle XCPOracle Sparc Enterprise M3000 ServerOracle Sparc Enterprise M4000 ServerOracle Sparc Enterprise M5000 Server+2 | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in Oracle SPARC Enterprise M3000, M4000, M5000, M8000, and M9000 XCP 1101 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to XSCF Control Package (XCP). | |
| Modificada | Alta (10) | 2.1% | — | Oracle SysfwOracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Sparc T3-1+3 | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in Sun Integrated Lights Out Manager (ILOM) in SysFW 8.1.0.a and earlier for various Oracle SPARC T3, SPARC Netra T3, Sun Blade, and Sun Fire servers allows remote attackers to affect confidentiality, integrity, and availability, related to ILOM. | |
| Modificada | Baja (2.1) | 0.33% | — | Oracle SysfwOracle Netra Sparc T3-1Oracle Sparc T3-1Oracle Sparc T3-1b+19 | 20/7/2011 | 16/6/2026 | Unspecified vulnerability in Sun Integrated Lights Out Manager in Oracle SysFW 8.0.3.b or earlier for various Oracle SPARC T3, SPARC Netra T3, Sun Blade, and Sun Fire servers allows local users to affect confidentiality via unknown vectors. |