Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 5.2% | — | Autodesk SketchbookAutodesk Sketchbook ExpressAutodesk Sketchbook FOR Enterprise 2014Autodesk Sketchbook PRO | 2/4/2014 | 16/6/2026 | Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a PSD file. | |
| Modificada | Media (5) | 1.2% | — | IBM Cognos Express | 25/3/2014 | 16/6/2026 | IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext information by leveraging knowledge of a static decryption key. | |
| Modificada | Media (5) | 1.7% | — | IBM Cognos Express | 25/3/2014 | 16/6/2026 | The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encrypted credentials via unspecified vectors. | |
| Modificada | Media (6.8) | 0.82% | — | IBM Cognos Express | 25/3/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (4.3) | 2.4% | — | Intel Expressway Cloud Access 360Mcafee Cloud Identity ManagerMcafee Cloud Single Sign ON | 18/3/2014 | 17/6/2026 | Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown… | |
| Modificada | Media (4) | 1.4% | — | Cisco Unified Contact Center Express Editor Software | 27/2/2014 | 17/6/2026 | Cisco Unified Contact Center Express (Unified CCX) does not properly restrict the content of the CCMConfig page, which allows remote authenticated users to obtain sensitive information by examining this content, aka Bug ID CSCum95575. | |
| Modificada | Media (4) | 1.3% | — | Cisco Unified Contact Center Express Editor Software | 27/2/2014 | 17/6/2026 | The disaster recovery system (DRS) in Cisco Unified Contact Center Express (Unified CCX) allows remote authenticated users to obtain sensitive information by reading extraneous fields in an HTML document, aka Bug ID CSCum95536. | |
| Modificada | Media (6.8) | 0.82% | — | Cisco Unified Contact Center Express Editor Software | 27/2/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCum95502. | |
| Modificada | Media (5) | 1.3% | — | Blackberry Enterprise ServiceBlackberry Universal Device ServiceBlackberry Enterprise ServerBlackberry Enterprise Server Express | 14/2/2014 | 17/6/2026 | BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Express for Exchange through 5.0.4, Enterprise Server for Domino through 5.0.4 MR6, Enterprise Server for Exchange through 5.0.4 MR6, and Enterprise Server for GroupWise… | |
| Modificada | Media (6.9) | 0.36% | — | Intel C202 ChipsetIntel C204 ChipsetIntel C206 ChipsetIntel C216 Chipset+6 | 12/9/2013 | 16/6/2026 | Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked,… | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | BMC Service Desk Express | 29/7/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or the (3) HelpPage parameter to commonhelp.aspx. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | BMC Service Desk Express | 29/7/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) TABLE_WIDGET_2, (4) browserDateTimeInfo, or (5) browserNumberInfo cookie parameter to DashBoardGUI.aspx; or the (6) UID… | |
| Modificada | Media (5) | 1.2% | — | Cisco Unified Contact Center Express Editor Software | 24/4/2013 | 16/6/2026 | The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows remote attackers to read arbitrary scripts by visiting the scripts repository directory, aka Bug ID CSCuf77546. | |
| Modificada | Media (4.3) | 10% | 💥 Exploit | Cisco Unity Express Software | 13/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud87527. | |
| Modificada | Media (6.8) | 1.2% | 💥 Exploit | Cisco Unity Express SoftwareCisco Unity Express | 6/2/2013 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910. | |
| Modificada | Alta (9.3) | 32% | 💥 PoC | Microsoft XML Core ServicesMicrosoft Windows 7Microsoft Windows 8Microsoft Windows Server 2003+11 | 9/1/2013 | 16/6/2026 | Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability." | |
| Modificada | Alta (8.8) | 28% | — | Microsoft XML Core ServicesMicrosoft Windows 7Microsoft Windows 8Microsoft Windows Server 2003+11 | 9/1/2013 | 16/6/2026 | Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability." | |
| Modificada | Media (5.8) | 0.57% | — | OscommercePaypal Payflow PRO Express Checkout | 4/11/2012 | 16/6/2026 | The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Akunamachata Paypal Express ModuleOscommerce | 4/11/2012 | 16/6/2026 | The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Alta (7.5) | 1.3% | — | Mystorexpress Tienda Virtual | 4/10/2012 | 16/6/2026 | SQL injection vulnerability in art_catalogo.php in MyStore Xpress Tienda Virtual 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mystorexpress Tienda Virtual | 4/10/2012 | 16/6/2026 | SQL injection vulnerability in art_detalle.php in MyStore Xpress Tienda Virtual allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.2) | 0.46% | — | Intel Sinit Authenticated Code ModuleIntel C202 ChipsetIntel C204 ChipsetIntel C206 Chipset+16 | 15/9/2012 | 16/6/2026 | Buffer overflow in Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) in Intel Q67 Express, C202, C204, C206 Chipsets, and Mobile Intel QM67, and QS67 Chipset before 2nd_gen_i5_i7_SINIT_51.BIN Express; Intel Q57, 3450 Chipsets and Mobile Intel QM57 and QS57 Express Chipset before… | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Itechscripts Travelon Express | 13/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameter to (1) holiday.php or (2) holiday_book.php, (3) id parameter to pages.php, (4) fid parameter to admin/airline-edit.php, or (5) cid parameter to admin/customer-edit.php. | |
| Modificada | Alta (7.8) | 1.7% | — | Oracle Application Express Listener | 17/7/2012 | 16/6/2026 | Unspecified vulnerability in the Oracle Application Express Listener component in Oracle Application Express Listener 1.1-ea, 1.1.1, 1.1.2, and 1.1.3 allows remote attackers to affect confidentiality via unknown vectors. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+14 | 22/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter. |