Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
729 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | BMC Service Desk Express | 29/7/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) TABLE_WIDGET_2, (4) browserDateTimeInfo, or (5) browserNumberInfo cookie parameter to DashBoardGUI.aspx; or the (6) UID… | |
| Modificada | Media (5) | 1.2% | — | Cisco Unified Contact Center Express Editor Software | 24/4/2013 | 16/6/2026 | The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows remote attackers to read arbitrary scripts by visiting the scripts repository directory, aka Bug ID CSCuf77546. | |
| Modificada | Media (4.3) | 10% | 💥 Exploit | Cisco Unity Express Software | 13/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud87527. | |
| Modificada | Media (6.8) | 1.2% | 💥 Exploit | Cisco Unity Express SoftwareCisco Unity Express | 6/2/2013 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910. | |
| Modificada | Alta (9.3) | 32% | 💥 PoC | Microsoft XML Core ServicesMicrosoft Windows 7Microsoft Windows 8Microsoft Windows Server 2003+11 | 9/1/2013 | 16/6/2026 | Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability." | |
| Modificada | Alta (8.8) | 28% | — | Microsoft XML Core ServicesMicrosoft Windows 7Microsoft Windows 8Microsoft Windows Server 2003+11 | 9/1/2013 | 16/6/2026 | Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability." | |
| Modificada | Media (5.8) | 0.57% | — | OscommercePaypal Payflow PRO Express Checkout | 4/11/2012 | 16/6/2026 | The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Akunamachata Paypal Express ModuleOscommerce | 4/11/2012 | 16/6/2026 | The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Alta (7.5) | 1.3% | — | Mystorexpress Tienda Virtual | 4/10/2012 | 16/6/2026 | SQL injection vulnerability in art_catalogo.php in MyStore Xpress Tienda Virtual 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mystorexpress Tienda Virtual | 4/10/2012 | 16/6/2026 | SQL injection vulnerability in art_detalle.php in MyStore Xpress Tienda Virtual allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.2) | 0.46% | — | Intel Sinit Authenticated Code ModuleIntel C202 ChipsetIntel C204 ChipsetIntel C206 Chipset+16 | 15/9/2012 | 16/6/2026 | Buffer overflow in Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) in Intel Q67 Express, C202, C204, C206 Chipsets, and Mobile Intel QM67, and QS67 Chipset before 2nd_gen_i5_i7_SINIT_51.BIN Express; Intel Q57, 3450 Chipsets and Mobile Intel QM57 and QS57 Express Chipset before… | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Itechscripts Travelon Express | 13/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameter to (1) holiday.php or (2) holiday_book.php, (3) id parameter to pages.php, (4) fid parameter to admin/airline-edit.php, or (5) cid parameter to admin/customer-edit.php. | |
| Modificada | Alta (7.8) | 1.7% | — | Oracle Application Express Listener | 17/7/2012 | 16/6/2026 | Unspecified vulnerability in the Oracle Application Express Listener component in Oracle Application Express Listener 1.1-ea, 1.1.1, 1.1.2, and 1.1.3 allows remote attackers to affect confidentiality via unknown vectors. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+14 | 22/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter. | |
| Modificada | Media (6.5) | 5.1% | 💥 Exploit | IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+14 | 22/6/2012 | 16/6/2026 | SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet… | |
| Modificada | Media (6.5) | 3.8% | 💥 Exploit | Itechscripts Travelon Express | 27/5/2012 | 16/6/2026 | Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) airline-edit.php, (2) hotel-image-add.php, or (3) hotel-add.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Itechscripts Travelon Express | 27/5/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the holiday name field to (1) holiday_add.php or (2) holiday_view.php. | |
| Modificada | Media (5) | 2.3% | — | Cisco Unified Contact Center Express | 2/5/2012 | 16/6/2026 | Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834. | |
| Modificada | Alta (10) | 62% | 💥 Exploit | HP Data Protector Express | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors. | |
| Modificada | Alta (10) | 10% | — | HP Data Protector Express | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1498. | |
| Modificada | Alta (10) | 10% | — | HP Data Protector Express | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1393. | |
| Modificada | Alta (10) | 10% | — | HP Data Protector Express | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1392. | |
| Modificada | Alta (9.3) | 22% | 💥 Exploit | Microsoft Expression Design | 13/3/2012 | 16/6/2026 | Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .xpr or .DESIGN file, aka "Expression Design… | |
| Modificada | Alta (7.5) | 1.8% | — | IBM Tivoli Provisioning Manager Express FOR Software Distribution | 6/3/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute arbitrary SQL commands via (1) a SOAP message to the Printer.getPrinterAgentKey function in the SoapServlet servlet, (2) the User.updateUserValue function in the… | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | IBM Tivoli Provisioning Manager Express FOR Software Distribution | 6/3/2012 | 16/6/2026 | Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file. |