Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—3com Superstack 3 Switch 440025/10/200616/6/2026
3Com Switch SS3 4400 switches, firmware 5.11, 6.00 and 6.10 and earlier, allow remote attackers to read the SNMP Read-Write Community string and conduct unauthorized actions via unspecified "normally restricted management packets on the device" that cause the community string to be returned.
ModificadaMedia (6.5)65%—Ipswitch WS FTP ServerProgress WS FTP Server26/9/200616/6/2026
Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote authenticated attack vectors via the (1) XCRC, (2) XMD5, and (3) XSHA1 commands. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong…
ModificadaMedia (5)32%—Ipswitch WS FTP ServerProgress WS FTP Server26/9/200616/6/2026
Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, prevents certain sensitive information from being displayed in the (1) Files and (2) Summary tabs. NOTE: in the early publication of this identifier on 20060926, the description was used for…
ModificadaAlta (7.5)4.2%💥 ExploitIpswitch WS FTP Server25/9/200616/6/2026
Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.
ModificadaMedia (6.5)85%💥 ExploitIpswitch WS FTP ServerProgress WS FTP Server19/9/200616/6/2026
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.
ModificadaAlta (7.5)61%💥 ExploitIpswitch Imail PlusIpswitch Imail Secure ServerIpswitch Collaboration Suite8/9/200616/6/2026
Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character.
ModificadaMedia (5)1.3%—Cisco Content Services Switch 1100025/8/200616/6/2026
The ArrowPoint cookie functionality for Cisco 11000 series Content Service Switches specifies an internal IP address if the administrator does not specify a string option, which allows remote attackers to obtain sensitive information.
ModificadaMedia (5)4.4%—HP Procurve Switch 3500ylHP Procurve Switch 5400zlHP Procurve Switch 6200yl7/8/200616/6/2026
Hewlett-Packard (HP) ProCurve 3500yl, 6200yl, and 5400zl switches with software before K.11.33 allow remote attackers to cause a denial of service (possibly memory leak or system crash) via unknown vectors.
ModificadaMedia (6.4)2.5%—Ipswitch Collaboration SuiteIpswitch Secure Server13/7/200616/6/2026
Premium Anti-Spam in Ipswitch IMail Secure Server 2006 and Collaboration Suite 2006 Premium, when using a certain .dat file in the StarEngine /data directory from 20060630 or earlier, does not properly receive and implement bullet signature updates, which allows context-dependent attackers to use the server for spam…
ModificadaAlta (7.5)7.4%💥 ExploitIpswitch Whatsup22/5/200616/6/2026
Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".
ModificadaMedia (5)3.8%—Ipswitch Whatsup Professional15/5/200616/6/2026
Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)2.5%—Ipswitch Whatsup Professional15/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via unknown vectors in (1) NmConsole/Tools.asp and (2) NmConsole/DeviceSelection.asp. NOTE: the provenance of this information is…
ModificadaMedia (5)3.5%—Ipswitch Whatsup Professional15/5/200616/6/2026
Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain source code for scripts via a trailing dot in a request to NmConsole/Login.asp.
ModificadaMedia (4.3)4.5%💥 ExploitIpswitch Whatsup Professional15/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b)…
ModificadaMedia (5)5.5%—Ipswitch Whatsup Professional15/5/200616/6/2026
NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensitive information about network nodes via a modified nDeviceGroupID parameter.
ModificadaMedia (5)3.8%—Ipswitch Whatsup Professional15/5/200616/6/2026
NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium generates different error messages in a way that allows remote attackers to enumerate valid usernames. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaMedia (5)3.1%—Ipswitch Whatsup Professional15/5/200616/6/2026
NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users to other websites via the (1) sCancelURL and possibly (2) sRedirectUrl parameters.
ModificadaMedia (5)1.9%—Cisco Content Services Switch 115005/4/200616/6/2026
Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) "valid, but obsolete" or (2) "specially crafted" HTTP requests.
ModificadaMedia (5)16%💥 ExploitIpswitch Whatsup28/2/200616/6/2026
NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving missing "[" (open bracket) or "["…
ModificadaMedia (5)64%💥 ExploitIpswitch Whatsup Small Business31/12/200516/6/2026
Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022).
ModificadaMedia (6.5)7.4%—Ipswitch Collaboration Suite31/12/200516/6/2026
Buffer overflow in the IMAP daemon in Ipswitch Collaboration Suite 2006.02 and earlier allows remote authenticated users to execute arbitrary code via a long FETCH command.
ModificadaMedia (4)11%—Ipswitch Imail ServerIpswitch Collaboration Suite7/12/200516/6/2026
The IMAP server in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to cause a denial of service (crash) via a long argument to the LIST command, which causes IMail Server to reference invalid memory.
ModificadaAlta (7.5)4.7%—Ipswitch Imail ServerIpswitch Collaboration Suite7/12/200516/6/2026
Format string vulnerability in the SMTP service in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to execute arbitrary code via format string specifiers to the (1) EXPN, (2) MAIL, (3) MAIL FROM, and (4) RCPT TO commands.
ModificadaMedia (5)1.0%—Cisco Content Services Switch 115002/11/200516/6/2026
Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation.
ModificadaBaja (2.1)0.35%—Mcdata Intrepid 6064 Director SwitchMcdata Intrepid 6140 Director SwitchMcdata Sphereon 4300 Fabric SwitchMcdata Sphereon 4500 Fabric Switch7/8/200516/6/2026
Unknown vulnerability in Sun McData switches and directors 4300, 4500, 6064, and 6140 before E/OS 6.0.0 may allow attackers to cause a denial of service (connectivity and array access loss) via a network broadcast storm.