Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 14% | 💥 Exploit | Trustwave ModsecurityOpensuse | 15/7/2013 | 16/6/2026 | The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header. | |
| Modificada | Alta (7.5) | 4.2% | — | Trustwave ModsecurityOpensuseFedoraproject FedoraDebian Linux | 25/4/2013 | 16/6/2026 | ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability. | |
| Modificada | Media (5) | 13% | 💥 Exploit | Trustwave ModsecurityOpensuseFedoraproject Fedora | 28/12/2012 | 16/6/2026 | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Trustedcomputinggroup Trousers | 26/11/2012 | 16/6/2026 | tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003. | |
| Modificada | Alta (9.3) | 3.8% | 💥 Exploit | Quest Intrust | 17/11/2012 | 16/6/2026 | The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument. | |
| Modificada | Alta (10) | 69% | 💥 Exploit | Quest Intrust | 17/11/2012 | 16/6/2026 | The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers to execute arbitrary code via a memory address in the first argument, related to an "uninitialized pointer." | |
| Modificada | Media (4.3) | 3.3% | — | Trustwave ModsecurityOpensuseDebian LinuxOracle Http Server | 22/7/2012 | 16/6/2026 | ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as… | |
| Modificada | Media (4.3) | 2.9% | — | Trustwave ModsecurityOpensuse | 22/7/2012 | 16/6/2026 | ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a… | |
| Modificada | Media (4.3) | 98% | — | Antiy AVL SDKCA Etrust VET AntivirusDrweb Dr.web AntivirusEmsisoft Anti-malware+10 | 21/3/2012 | 16/6/2026 | The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7,… | |
| Modificada | Media (4.3) | 100% | — | Aladdin EsafeAntiy AVL SDKCA Etrust VET AntivirusCAT Quick Heal+10 | 21/3/2012 | 16/6/2026 | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA… | |
| Modificada | Media (4.3) | 78% | — | Aladdin EsafeCA Etrust VET AntivirusFortinet AntivirusNorman Antivirus & Antispyware+1 | 21/3/2012 | 16/6/2026 | The ELF file parser in Norman Antivirus 6.06.12, eSafe 7.0.17.0, CA eTrust Vet Antivirus 36.1.8511, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified identsize field. NOTE: this may later be SPLIT into multiple CVEs if… | |
| Modificada | Media (5) | 1.3% | — | Michael Armbruster Arctic FOX CMS | 23/9/2011 | 16/6/2026 | Arctic Fox CMS 0.9.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by acp/includes/edit.inc.php and certain other files. | |
| Modificada | Media (5) | 1.1% | — | Trustwave Webdefend | 5/5/2011 | 16/6/2026 | Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event collection table via requests to the management port, a different vulnerability than CVE-2011-0756. | |
| Modificada | Media (5) | 1.1% | — | Trustwave Webdefend | 5/5/2011 | 16/6/2026 | The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote console GUI to connect to the management port. | |
| Modificada | Alta (10) | 8.2% | — | CA Etrust Secure Content ManagerCA Gateway Security | 10/2/2011 | 16/6/2026 | The eCS component (ECSQdmn.exe) in CA ETrust Secure Content Manager 8.0 and CA Gateway Security 8.1 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted request to port 1882, involving an incorrect integer calculation and a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | CA Etrust Pestpatrole Ppctl.dll Activex | 8/12/2009 | 16/6/2026 | Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to the Initialize method. | |
| Modificada | Media (4.3) | 2.4% | — | Broadcom Anti-virusBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti-virus SDKBroadcom Common Services+29 | 13/10/2009 | 16/6/2026 | Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to… | |
| Modificada | Alta (9.3) | 7.6% | — | Broadcom Anti-virusBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti-virus SDKBroadcom Common Services+28 | 13/10/2009 | 16/6/2026 | Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to… | |
| Modificada | Alta (7.8) | 0.29% | — | Trustport AntivirusTrustport PC Security | 30/9/2009 | 16/6/2026 | TrustPort Antivirus before 2.8.0.2266 and PC Security before 2.0.0.1291 use weak permissions (Everyone: Full Control) for files under %PROGRAMFILES%, which allows local users to gain privileges by replacing executables with Trojan horse programs. | |
| Modificada | Media (4.3) | 3.0% | — | Trustwave ModsecurityFedoraproject Fedora | 3/6/2009 | 16/6/2026 | The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method. | |
| Modificada | Media (5) | 14% | 💥 Exploit | Trustwave ModsecurityFedoraproject Fedora | 3/6/2009 | 16/6/2026 | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference. | |
| Modificada | Alta (10) | 4.3% | — | Broadcom Anti-spywareBroadcom Anti-spyware FOR THE EnterpriseBroadcom Anti-virusBroadcom Anti-virus FOR THE Enterprise+15 | 28/1/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a… | |
| Modificada | Alta (7.6) | 2.2% | — | Intel Trusted Execution Technology | 7/1/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot. NOTE: as of 20090107, the only disclosure is a vague pre-advisory with no actionable information. However,… | |
| Modificada | Alta (9.3) | 2.7% | — | CA Etrust AntivirusAIMicrosoft Internet ExplorerAI | 12/12/2008 | 16/6/2026 | CA eTrust Antivirus 31.6.6086, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated… | |
| Modificada | Alta (7.1) | 32% | 💥 PoC | BSDBsdi BSD OSCisco IOSDragonflybsd+15 | 20/10/2008 | 16/6/2026 | The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as… |