Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
539 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.6% | — | Surfcontrol Superscout Email Filter | 31/12/2002 | 16/6/2026 | SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a buffer overflow. | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Independent Solution Simple Site SearcherIndependent Solution Super Site Searcher | 31/12/2002 | 16/6/2026 | site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords. | |
| Modificada | Alta (7.5) | 0.98% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | UserManager.js en el Web Reports Server para SurfControl SuperScout WebFilter utiliza cifrado débil para las funciones de administrador, lo cual permite a atacantes remotos descifrar la contraseña de administrador mediante una clave incluida en el código de una función Javascript. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | Vulnerabilidad de Atravesamiento de directorios en los Servidores Web de Informes para SurfControl SuperScout WebFilter que permite a los atantes la lectura arbitraria de ficheros vía peticiones HTTP que contengan la secuencia "..." (tres puntos) | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | Vulnerabilidades de Inyección de SQL en el Servidor de Informes (Web Reports Server) de SurfControl SuperScout WebFilter permite a los atacantes remotos la ejecución de consultas SQL arbitrarias, mediante la opción RunReport en SimpleBar.dll, y posiblemente otras DLLs. | |
| Modificada | Media (5) | 1.8% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | El Servidor de Informes (Web Reports Server) de SurfControl SuperScout WebFilter permite a atacantes remotos causar la denegación de servicios (consumo de CPU) mediante una petición larga GET, posiblemente debido a una desbordamiento de búfer. | |
| Modificada | Alta (7.2) | 0.76% | 💥 Exploit | William Deich Super | 12/8/2002 | 16/6/2026 | Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument. | |
| Modificada | Media (4.6) | 0.35% | — | Surfcontrol Superscout WEB Filter | 26/2/2002 | 16/6/2026 | SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | 3com Superstack II PS HUB 40 Firmware | 12/7/2001 | 16/6/2026 | The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing. | |
| Modificada | Baja (2.1) | 0.41% | — | Borland Software Interbase Superserver | 14/11/2000 | 16/6/2026 | Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes. | |
| Modificada | Baja (2.1) | 0.38% | — | Surfcontrol Superscout | 3/2/2000 | 16/6/2026 | surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions. | |
| Modificada | Alta (7.5) | 1.1% | — | 3com Superstack II HUB | 30/8/1999 | 16/6/2026 | Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities. | |
| Modificada | Media (5) | 1.9% | — | Cisco Catalyst 12xx Supervisor SoftwareCisco Catalyst 29xx Supervisor SoftwareCisco Catalyst 5xxx Supervisor Software | 1/3/1999 | 16/6/2026 | Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload. |