Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.5% | — | HP Windows Event LOG SmartconnectorHP Arcsight C1000 ApplianceHP Arcsight C1300 ApplianceHP Arcsight C3200 Appliance+3 | 19/7/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 allows remote attackers to inject arbitrary web script or HTML via the Windows XP variable in a file. | |
| Modificada | Media (5.8) | 0.95% | — | Oracle Mysql Connector/net | 29/4/2010 | 16/6/2026 | MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | IBM Lotus Notes Connector | 1/9/2009 | 16/6/2026 | A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 allows remote attackers to cause a denial of service (Internet Explorer crash) by referencing the control's CLSID in the classid attribute of an OBJECT element. | |
| Modificada | Media (4.3) | 0.32% | — | SUN RAY Server SoftwareSUN RAY Windows Connector | 11/12/2008 | 16/6/2026 | Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the… | |
| Modificada | Baja (3.7) | 19% | 💥 PoC | Openbsd OpensshSSH Tectia ClientSSH Tectia ConnectorSSH Tectia Connectsecure+1 | 19/11/2008 | 16/6/2026 | Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J… | |
| Modificada | Baja (2.1) | 0.44% | — | Hpsi Acf2 ConnectorHpsi Active Directory ConnectorHpsi Bidir Dirx ConnectorHpsi Edirectory Connector+7 | 11/9/2008 | 16/6/2026 | Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1.02 and earlier, HPSI OID Connector 1.02 and earlier, HPSI IBM… | |
| Modificada | Alta (10) | 84% | 💥 Exploit | BEA Weblogic ServerBEA Systems Apache Connector IN Weblogic ServerBEA Systems Weblogic ServerOracle Weblogic Server | 22/7/2008 | 16/6/2026 | Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request. | |
| Modificada | Alta (9) | 3.8% | — | Hpsi Active Directory Bidirectional Ldap Connector | 17/7/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in HP Select Identity (HPSI) Active Directory Bidirectional LDAP Connector 2.20, 2.20.001, 2.20.002, and 2.30 allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5) | 13% | — | Apache Tomcat JK WEB Server Connector | 25/5/2007 | 16/6/2026 | mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Cabron Connector | 19/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CabronServiceFolder parameter. | |
| Modificada | Alta (7.5) | 82% | 💥 Exploit | Apache Tomcat JK WEB Server Connector | 4/3/2007 | 16/6/2026 | Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker… | |
| Modificada | Media (5) | 1.4% | — | SSH Tectia ClientSSH Tectia ConnectorSSH Tectia ManagerSSH Tectia Server | 24/10/2006 | 16/6/2026 | SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents Tectia from correctly… | |
| Modificada | Alta (7.2) | 0.34% | — | SSH Tectia ClientSSH Tectia ConnectorSSH Tectia ManagerSSH Tectia Server | 23/8/2006 | 16/6/2026 | Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its… | |
| Modificada | Media (6.4) | 2.5% | — | SAP Business Connector | 16/2/2006 | 16/6/2026 | Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the grace period has ended. NOTE: SAP Business… | |
| Modificada | Media (4) | 2.7% | 💥 Exploit | SAP Business Connector | 16/2/2006 | 16/6/2026 | WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Enterprise Heart Enterprise Connector | 29/12/2005 | 16/6/2026 | SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Enterprise Heart Enterprise Connector | 29/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php. | |
| Modificada | Media (4.6) | 1.3% | — | Microsoft Outlook Connector | 2/5/2005 | 16/6/2026 | Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy. | |
| Modificada | Alta (7.5) | 90% | 💥 Exploit | OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+1 | 12/8/2002 | 16/6/2026 | Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3. | |
| Modificada | Alta (7.5) | 8.2% | — | OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+1 | 12/8/2002 | 16/6/2026 | OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (5) | 36% | 💥 Exploit | OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+1 | 12/8/2002 | 16/6/2026 | The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings. |