Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.0% | — | Dropwizard ValidationOracle Blockchain Platform | 24/2/2020 | 17/6/2026 | Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and… | |
| Modificada | Media (4.3) | 1.4% | — | EMC RSA Validation Manager | 22/6/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Validation Manager (RVM) 3.2 before build 201 allow remote attackers to inject arbitrary web script or HTML via the (1) displayMode or (2) wrapPreDisplayMode parameter. | |
| Modificada | Baja (3.5) | 1.0% | — | Webform Validation Project Webform Validation | 17/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a component name text. | |
| Modificada | Baja (2.1) | 1.0% | — | Svendecabooter Webform Validation | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with permissions to "update Webform nodes" to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.7% | — | Gamespy SDK Cd-key Validation Toolkit | 14/5/2005 | 16/6/2026 | Gamespy cd-key validation system allows remote attackers to cause a denial of service (cd-key already in use) by capturing and replaying a cd-key authorization session. | |
| Modificada | Media (5) | 1.8% | — | Gamespy Cd-key Validation System | 11/5/2005 | 16/6/2026 | GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the server the CD key is no longer in use. | |
| Modificada | Alta (7.5) | 1.6% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which… | |
| Modificada | Alta (7.5) | 2.5% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path. | |
| Modificada | Alta (7.5) | 2.3% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed. | |
| Modificada | Alta (7.5) | 4.1% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6)… |