Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 0.33% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Media (6.4) | 0.35% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Media (5.9) | 0.53% | — | HP 310s-14isk FirmwareHP 320-15ikbra FirmwareHP 320-15ikbrn FirmwareHP 320-15ikbrn Touch Firmware+64 | 2/10/2018 | 17/6/2026 | In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS. | |
| Modificada | Alta (7.5) | 2.6% | — | CGI Rescue Blobee | 13/6/2015 | 17/6/2026 | CGI RESCUE BloBee 1.20 and earlier allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Gameloft Wonder ZOO - Animal Rescue ! | 9/9/2014 | 17/6/2026 | The Wonder Zoo - Animal rescue ! (aka com.gameloft.android.ANMP.GloftZRHM) application 1.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.3% | — | CGI Rescue Rescue | 26/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CGI RESCUE Trees before 2.11 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Media (4.3) | 1.1% | — | CGI Rescue CGI WEB Mailer | 8/5/2009 | 16/6/2026 | CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form. | |
| Modificada | Media (5) | 1.2% | — | CGI Rescue Form2mail | 8/5/2009 | 16/6/2026 | Unspecified vulnerability in CGI RESCUE FORM2MAIL before 1.42 allows remote attackers to send email to arbitrary recipients via a web form. | |
| Modificada | Media (5) | 1.2% | — | CGI Rescue Minibbs22 | 8/5/2009 | 16/6/2026 | Unspecified vulnerability in CGI RESCUE MiniBBS22 before 1.01 allows remote attackers to send email to arbitrary recipients via unknown vectors. | |
| Modificada | Media (4.3) | 1.2% | — | CGI Rescue Minibbs | 8/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CGI RESCUE MiniBBS 8t before 8.95t, 8 before 8.95, 9 before 9.08, and 10 before 10.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.6% | — | Cgi-rescue Kannibbs2000Cgi-rescue Kannibbs2000i | 26/12/2008 | 16/6/2026 | Directory traversal vulnerability in CGI RESCUE KanniBBS2000 (aka KanniBBS2000i, MiniBBS2000, and MiniBBS2000i) before 1.03 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (10) | 1.5% | — | Mondo Rescue | 2/4/2008 | 16/6/2026 | Unspecified vulnerability in Mondo Rescue before 2.2.5 has unknown impact and attack vectors, related to the use of (1) /tmp and (2) MINDI_CACHE. | |
| Modificada | Media (5) | 1.8% | — | Cgi-rescue Shopping Basket Professional | 4/9/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi. | |
| Modificada | Alta (10) | 3.2% | — | Datarescue IDA PRO | 24/3/2007 | 16/6/2026 | The processor_request function in the debugger server for DataRescue IDA Pro 5.0 and 5.1 does not verify that authentication has taken place before invoking the perform_request function, which allows remote attackers to perform unauthorized actions. | |
| Modificada | Alta (7.5) | 1.4% | — | Cgi-rescue Shopping Basket Professional | 30/1/2007 | 16/6/2026 | CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Cgi-rescue Webform | 29/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CGI-RESCUE WebFORM 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.5% | — | Cgi-rescue Mail F W System | 24/8/2006 | 16/6/2026 | CRLF injection vulnerability in CGI-Rescue Mail F/W System (formd) before 8.3 allows remote attackers to spoof e-mails and inject e-mail headers via unspecified vectors in (1) mail.cgi and (2) query.cgi. | |
| Modificada | Media (5) | 1.5% | — | Cgi-rescue Form2mail | 12/6/2006 | 16/6/2026 | Unspecified vulnerability in CGI-RESCUE FORM2MAIL 1.21 and earlier allows remote attackers to inject email headers, which facilitates sending spam messages. NOTE: the details for this issue are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.7% | — | Cgi-rescue Webform | 12/6/2006 | 16/6/2026 | Unspecified vulnerability in CGI-RESCUE WebFORM 4.1 and earlier allows remote attackers to inject email headers, which facilitates sending spam messages. NOTE: the details for this issue are obtained from third party information. | |
| Modificada | Alta (7.5) | 3.3% | — | Datarescue IDA PRO | 2/5/2005 | 16/6/2026 | Format string vulnerability in DataRescue Interactive Disassembler and Debugger (IDA) Pro 4.7.0.830 allows remote attackers or local users to cause a denial of service (CPU consumption or application crash) and possibly execute arbitrary code via format string specifiers in a dynamic link library (DLL) name. | |
| Modificada | Alta (7.5) | 2.7% | — | Datarescue IDA | 24/1/2005 | 16/6/2026 | Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name. |