Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

571 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)3.5%—HP Windows Event LOG SmartconnectorHP Arcsight C1000 ApplianceHP Arcsight C1300 ApplianceHP Arcsight C3200 Appliance+319/7/201116/6/2026
Cross-site scripting (XSS) vulnerability in Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 allows remote attackers to inject arbitrary web script or HTML via the Windows XP variable in a file.
ModificadaMedia (5.8)0.95%—Oracle Mysql Connector/net29/4/201016/6/2026
MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate.
ModificadaMedia (4.3)3.5%💥 ExploitIBM Lotus Notes Connector1/9/200916/6/2026
A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 allows remote attackers to cause a denial of service (Internet Explorer crash) by referencing the control's CLSID in the classid attribute of an OBJECT element.
ModificadaMedia (4.3)0.32%—SUN RAY Server SoftwareSUN RAY Windows Connector11/12/200816/6/2026
Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the…
ModificadaBaja (3.7)19%💥 PoCOpenbsd OpensshSSH Tectia ClientSSH Tectia ConnectorSSH Tectia Connectsecure+119/11/200816/6/2026
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J…
ModificadaBaja (2.1)0.44%—Hpsi Acf2 ConnectorHpsi Active Directory ConnectorHpsi Bidir Dirx ConnectorHpsi Edirectory Connector+711/9/200816/6/2026
Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1.02 and earlier, HPSI OID Connector 1.02 and earlier, HPSI IBM…
ModificadaAlta (10)84%💥 ExploitBEA Weblogic ServerBEA Systems Apache Connector IN Weblogic ServerBEA Systems Weblogic ServerOracle Weblogic Server22/7/200816/6/2026
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
ModificadaAlta (9)3.8%—Hpsi Active Directory Bidirectional Ldap Connector17/7/200816/6/2026
Multiple unspecified vulnerabilities in HP Select Identity (HPSI) Active Directory Bidirectional LDAP Connector 2.20, 2.20.001, 2.20.002, and 2.30 allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (5)13%—Apache Tomcat JK WEB Server Connector25/5/200716/6/2026
mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory…
ModificadaAlta (7.5)2.8%💥 ExploitCabron Connector19/4/200716/6/2026
PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CabronServiceFolder parameter.
ModificadaAlta (7.5)82%💥 ExploitApache Tomcat JK WEB Server Connector4/3/200716/6/2026
Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker…
ModificadaMedia (5)1.4%—SSH Tectia ClientSSH Tectia ConnectorSSH Tectia ManagerSSH Tectia Server24/10/200616/6/2026
SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents Tectia from correctly…
ModificadaAlta (7.2)0.34%—SSH Tectia ClientSSH Tectia ConnectorSSH Tectia ManagerSSH Tectia Server23/8/200616/6/2026
Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its…
ModificadaMedia (6.4)2.5%—SAP Business Connector16/2/200616/6/2026
Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the grace period has ended. NOTE: SAP Business…
ModificadaMedia (4)2.7%💥 ExploitSAP Business Connector16/2/200616/6/2026
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.
ModificadaAlta (7.5)1.4%💥 ExploitEnterprise Heart Enterprise Connector29/12/200516/6/2026
SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875.
ModificadaAlta (7.5)1.2%💥 ExploitEnterprise Heart Enterprise Connector29/11/200516/6/2026
Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php.
ModificadaMedia (4.6)1.3%—Microsoft Outlook Connector2/5/200516/6/2026
Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.
ModificadaAlta (7.5)90%💥 ExploitOpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+112/8/200216/6/2026
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
ModificadaAlta (7.5)8.2%—OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+112/8/200216/6/2026
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaMedia (5)36%💥 ExploitOpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+112/8/200216/6/2026
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.