Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.8%—Adremsoft Netcrunch16/12/202017/6/2026
AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private keys, private keys' passwords, and root passwords stored in the credential manager. Every administrator can read the ESX and Windows passwords stored in the credential manager.
ModificadaCrítica (9.8)1.8%—Adremsoft Netcrunch16/12/202017/6/2026
AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no other SSL certificate is installed, which allows remote attackers to defeat cryptographic protection mechanisms by…
ModificadaCrítica (9.8)1.1%—Adremsoft Netcrunch16/12/202017/6/2026
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
ModificadaMedia (5.5)0.28%—Adremsoft Netcrunch16/12/202017/6/2026
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted.
ModificadaAlta (7)0.43%—Linuxfoundation RuncDebian LinuxOpensuse LeapCanonical Ubuntu Linux+112/2/202017/6/2026
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due…
ModificadaAlta (7.5)4.4%—Linuxfoundation RuncDockerFedoraproject FedoraOpensuse Leap+625/9/201917/6/2026
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
ModificadaAlta (8.6)98%💥 ExploitDockerLinuxfoundation RuncRedhat Container Development KITRedhat Openshift+1511/2/201917/6/2026
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image,…
ModificadaMedia (6.5)1.2%—Cloudfoundry Garden-runc18/9/201817/6/2026
Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps.
ModificadaMedia (6.5)1.2%—Untrunc Project Untrunc20/7/201817/6/2026
Codec::parse in track.cpp in Untrunc through 2018-06-07 has a NULL pointer dereference via a crafted MP4 file because of improper interaction with libav.
ModificadaMedia (6.5)1.1%—Cloudfoundry Garden-runcCloudfoundry Cf-deployment30/4/201817/6/2026
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.
ModificadaAlta (8.8)0.92%—Cloudfoundry Cf-deploymentCloudfoundry Garden-runc-release29/3/201817/6/2026
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.
ModificadaAlta (7.8)0.39%—DockerLinuxfoundation RuncOpensuse1/6/201617/6/2026
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
ModificadaMedia (6.8)1.2%—Image Metadata Cruncher Project Image Metadata Cruncher19/2/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) image_metadata_cruncher[alt] or (2)…
ModificadaMedia (6.8)0.97%—Crunchify Facebook Members5/5/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify this plugin's settings.
ModificadaMedia (6.8)0.95%—Crunchify Foursquare-checkins26/4/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
ModificadaMedia (6.8)0.95%—Crunchify All-in-on-webmaster25/4/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the All in One Webmaster plugin before 8.2.4 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
ModificadaBaja (2.6)1.1%—Runcms25/7/201016/6/2026
Cross-site scripting (XSS) vulnerability in modules/headlines/magpierss/scripts/magpie_debug.php in RunCms 2.1, when the Headlines module is enabled, allows remote attackers to inject arbitrary web script or HTML via the url parameter.
ModificadaMedia (5)1.1%—Runcms27/10/200916/6/2026
RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to modules/contact/index.php or (2) uid[] parameter to userinfo.php, which leaks the installation path in an error message when these parameters are used in a call to the…
ModificadaMedia (6.5)1.1%—Runcms27/10/200916/6/2026
Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" feature, as demonstrated by modifying modules/system/cache/bademails.php using the "Prohibited: Emails" action, and other unspecified filters.
ModificadaMedia (6.5)0.90%—Runcms27/10/200916/6/2026
Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter to modules/forum/post.php and possibly (2) forum_id variable to modules/forum/class/class.permissions.php.
ModificadaMedia (6.5)0.81%💥 ExploitRuncms27/10/200916/6/2026
Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.
ModificadaMedia (4.3)1.4%💥 ExploitRuncms14/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter in a RankForumAdd action.
ModificadaMedia (6.8)0.62%—Runcms14/9/200916/6/2026
Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for requests that (1) add new administrators or (2) modify user profiles via a crafted request to system/admin.php.
ModificadaAlta (7.5)0.96%💥 ExploitRuncms Myannonces24/7/200916/6/2026
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.
ModificadaAlta (7.5)2.5%💥 ExploitRuncms Newbb Plus ModuleRuncms28/7/200816/6/2026
Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bbPath[path] parameter to votepolls.php and the (2) bbPath[root_theme] parameter to config.php, different vectors than CVE-2006-0659.…
Orbitaley — Vulnerabilidades