Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Redhat Up2date | 27/8/2003 | 16/6/2026 | up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised. | |
| Modificada | Media (5) | 2.0% | — | Pyramid Benhur Software Update | 31/12/2002 | 16/6/2026 | The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20. | |
| Modificada | Media (5) | 2.8% | — | Symantec Liveupdate | 25/6/2002 | 16/6/2026 | Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server. | |
| Modificada | Crítica (9.8) | 2.5% | — | Symantec Liveupdate | 5/10/2001 | 16/6/2026 | Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site. | |
| Modificada | Media (5) | 2.6% | — | Symantec Liveupdate | 5/10/2001 | 16/6/2026 | Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site. | |
| Modificada | Media (4.6) | 0.38% | — | Symantec Liveupdate | 14/8/2001 | 16/6/2026 | Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | CGI Script Center News Update | 19/12/2000 | 23/9/2026 | CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password. | |
| Modificada | Media (6.2) | 0.31% | — | Helix Code Gnome Updater | 20/10/2000 | 16/6/2026 | Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages. |