Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
729 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.8% | — | NEC Expresscluster X | 30/1/2016 | 17/6/2026 | Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Unified Contact Center Express | 26/1/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033. | |
| Modificada | Alta (7.5) | 3.5% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8384 and CVE-2015-8392. | |
| Modificada | Crítica (9.8) | 4.8% | — | Pcre Perl Compatible Regular Expression LibraryPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Alta (7.5) | 4.4% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client. | |
| Modificada | Alta (7.5) | 3.6% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion and buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a… | |
| Modificada | Crítica (9.8) | 4.7% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Crítica (9.8) | 3.9% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Alta (7.5) | 6.6% | — | Oracle LinuxPcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp… | |
| Modificada | Alta (7.3) | 3.6% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Crítica (9.8) | 6.9% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraOracle LinuxPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by… | |
| Modificada | Alta (7.5) | 5.6% | — | Oracle LinuxPcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object… | |
| Modificada | Alta (7.5) | 3.4% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp… | |
| Modificada | Crítica (9.8) | 6.1% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Media (6.4) | 4.0% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (partially… | |
| Modificada | Alta (7.5) | 5.3% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|((?'R')))H'Rk'Rf)|s(?'R'))))/ and /(?J:(?|(:(?|(?'R')(\z(?|(?'R')(\k'R')|((?'R')))k'R')|((?'R')))H'Ak'Rf)|s(?'R')))/ patterns, and related patterns with certain group… | |
| Modificada | Alta (7.5) | 4.4% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject Fedora | 2/12/2015 | 17/6/2026 | The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object… | |
| Modificada | Alta (7.5) | 4.0% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a… | |
| Modificada | Alta (7.2) | 0.61% | — | HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+3 | 4/11/2015 | 17/6/2026 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. | |
| Modificada | Alta (7.2) | 0.92% | 💥 Exploit | Vboxcomm Satellite Express Protocol | 21/9/2015 | 17/6/2026 | The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call. | |
| Modificada | Media (6.4) | 1.9% | — | Devexpress Ajax Control Toolkit | 18/8/2015 | 17/6/2026 | Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd. | |
| Modificada | Media (5) | 2.8% | — | Hotspotexpress Hotex Billing Manager | 16/4/2015 | 17/6/2026 | Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |
| Modificada | Media (4.3) | 1.9% | — | Hotspot Express Hotex Billing Manager | 14/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows remote attackers to inject arbitrary web script or HTML via the reply parameter. | |
| Modificada | Alta (10) | 4.3% | — | Cisco Expressway SoftwareCisco Telepresence ConductorCisco Telepresence Video Communication Server Software | 13/3/2015 | 17/6/2026 | The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Expressway SoftwareCisco Telepresence ConductorCisco Telepresence Video Communication Server Software | 13/3/2015 | 17/6/2026 | The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka… |