Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6)0.92%—HP System Management Homepage21/7/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitAdobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+1123/6/201517/6/2026
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
ModificadaMedia (6.4)8.3%—Haxx CurlHaxx LibcurlHP System Management HomepageOracle Enterprise Manager OPS Center+122/6/201517/6/2026
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
ModificadaMedia (5)50%—Redhat Enterprise LinuxApple MAC OS XPHPHP System Management Homepage+89/6/201517/6/2026
Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.
ModificadaMedia (5)14%—Fedoraproject FedoraCanonical Ubuntu LinuxDebian LinuxApple MAC OS X+424/4/201517/6/2026
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
ModificadaAlta (7.5)37%—Fedoraproject FedoraCanonical Ubuntu LinuxDebian LinuxHaxx Curl+524/4/201517/6/2026
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.
ModificadaMedia (5)13%—Haxx CurlCanonical Ubuntu LinuxDebian LinuxHaxx Libcurl+224/4/201517/6/2026
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
ModificadaMedia (6.8)1.6%—HP System Management HomepageHp-ux19/10/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (4.3)2.4%—HP System Management Homepage2/10/201417/6/2026
HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
ModificadaMedia (6)0.86%—HP System Management Homepage2/10/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (4.3)3.9%—HP System Management Homepage2/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.98%—HP System Management Homepage14/3/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (5)2.2%—HP System Management Homepage14/3/201416/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.3 allows remote attackers to obtain sensitive information via unknown vectors.
ModificadaMedia (4)1.9%—HP System Management Homepage23/9/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors.
ModificadaBaja (3.5)1.3%—HP System Management Homepage22/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)3.3%—HP System Management Homepage22/7/201316/6/2026
HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2356.
ModificadaBaja (2.1)0.53%—HP System Management Homepage22/7/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows local users to cause a denial of service via unknown vectors, aka ZDI-CAN-1676.
ModificadaMedia (4.3)2.5%—HP System Management Homepage22/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4)1.8%—HP System Management Homepage22/7/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2358, and CVE-2013-2359.
ModificadaMedia (4)1.8%—HP System Management Homepage22/7/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2358, and CVE-2013-2360.
ModificadaMedia (4)1.8%—HP System Management Homepage22/7/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2359, and CVE-2013-2360.
ModificadaMedia (4)1.8%—HP System Management Homepage22/7/201316/6/2026
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2358, CVE-2013-2359, and CVE-2013-2360.
ModificadaMedia (5)3.3%—HP System Management Homepage22/7/201316/6/2026
HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2363.
ModificadaMedia (5)3.5%—HP System Management Homepage22/7/201316/6/2026
HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2012-5217.
ModificadaMedia (5)3.5%—HP System Management Homepage22/7/201316/6/2026
HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2355.
Orbitaley — Vulnerabilidades