Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 11% | 💥 Exploit | Videowhisper Live Streaming Integration PluginVideowhisper Live Streaming Integration | 6/3/2014 | 17/6/2026 | Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to… | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Videowhisper Live Streaming Integration PluginVideowhisper Live Streaming Integration | 6/3/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4)… | |
| Modificada | Media (4.3) | 2.0% | — | Videowhisper Live Streaming Integration | 9/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter. NOTE: some of these details are obtained from… | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Datapower Xc10 Appliance FirmwareIBM Websphere Datapower Xc10 ApplianceIBM Websphere Datapower Service Gateway Xg45 Virtual Edition FirmwareIBM Websphere Datapower Service Gateway Xg45 Virtual Edition+10 | 28/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web… | |
| Modificada | Alta (9.3) | 2.6% | — | IBM Gentran Integration SuiteIBM Sterling B2B IntegratorIBM Sterling File GatewayIBM Sterling Integrator | 12/4/2013 | 16/6/2026 | Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Varnish Http Accelerator Integration Project Varnish | 27/3/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting. | |
| Modificada | Media (5.4) | 0.57% | — | IBM Webshere Cast Iron Cloud Integration | 22/2/2013 | 16/6/2026 | Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Media (6.8) | 1.1% | — | Oracle Hyperion Interactive ReportingOracle Essbase ServerOracle Hyperion Production Reporting ServerOracle Integration Services Server | 21/12/2012 | 16/6/2026 | Buffer overflow in the DataDirect ODBC driver, as used in Oracle Hyperion Interactive Reporting 11.1.2.1 and 11.1.2.2, Essbase Server 11.1.2.1 and 11.1.2.2, Production Reporting Server 11.1.2.1 and 11.1.2.2, and Integration Services Server 11.1.2.1 and 11.1.2.2 has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 8.8% | 💥 Exploit | Skysa APP BAR Integration Plugin | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter. | |
| Analizada | Alta (8.8) | 72% | ⚠ Explotación activa | Microsoft Commerce ServerMicrosoft Host Integration ServerMicrosoft OfficeMicrosoft Office WEB Components+3 | 15/8/2012 | 16/6/2026 | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2,… | |
| Modificada | Media (5) | 21% | — | Microsoft Host Integration Server | 12/10/2011 | 16/6/2026 | Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability." | |
| Modificada | Media (5) | 23% | 💥 Exploit | Microsoft Host Integration Server | 12/10/2011 | 16/6/2026 | Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability." | |
| Modificada | Media (5) | 1.7% | — | IBM Websphere Datapower XML Accelerator Xa35IBM Websphere Datapower XML Security Gateway Xs40IBM Websphere Datapower Datapower Integration Appliance Xi50IBM Websphere Datapower B2B Appliance Xb60+1 | 29/4/2010 | 16/6/2026 | The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers to cause a denial of service (interface outage) via malformed ICMP… | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Programmedintegration Pipl | 21/8/2009 | 16/6/2026 | Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attackers to execute arbitrary code via a long string in a (1) .pls or (2) .pl playlist file. | |
| Modificada | Alta (10) | 78% | — | Microsoft Host Integration Server 2000Microsoft Host Integration Server 2004Microsoft Host Integration Server 2006 | 15/10/2008 | 16/6/2026 | Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution… | |
| Modificada | Media (6.8) | 1.0% | — | BEA TuxedoBEA Weblogic IntegrationBEA Weblogic ServerBEA Weblogic Workshop+1 | 18/10/2007 | 16/6/2026 | BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands. | |
| Modificada | Media (6.8) | 2.4% | — | Mirc Advanced Integration Plugin | 18/8/2007 | 16/6/2026 | Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file. | |
| Modificada | Alta (7.8) | 1.7% | — | BEA Weblogic IntegrationBEA Weblogic Workshop | 16/5/2007 | 16/6/2026 | Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through SP6, when "deployed in an exploded format," allows remote attackers to list a WebLogic Workshop Directory (wlwdir) parent directory via unspecified vectors. | |
| Modificada | Alta (10) | 8.3% | 💥 Exploit | NET Integration Technologies Inc. Wvtftp | 26/10/2004 | 16/6/2026 | Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet. | |
| Modificada | Media (6.8) | 1.3% | — | BEA Liquid DataBEA Weblogic IntegrationBEA Weblogic Server | 20/10/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other… | |
| Modificada | Alta (7.2) | 0.34% | — | SAS BaseSAS Integration Technologies | 31/12/2002 | 16/6/2026 | sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault. | |
| Modificada | Alta (10) | 4.1% | — | HP Ldap-ux IntegrationHp-ux | 31/12/2002 | 16/6/2026 | Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users. | |
| Modificada | Alta (10) | 2.5% | — | SAS BaseSAS Integration Technologies | 31/12/2002 | 16/6/2026 | sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd. | |
| Modificada | Alta (7.5) | 1.3% | — | BEA Weblogic IntegrationBEA Weblogic Server | 31/12/2002 | 16/6/2026 | An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role… | |
| Modificada | Alta (7.2) | 0.43% | — | SAS BaseSAS Integration Technologies | 16/5/2002 | 16/6/2026 | Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument. |