Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

740 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.7%—NEC BladesystemcenterNEC ExpresssystemcenterNEC SigmasystemcenterNEC Virtualpccenter+119/5/201016/6/2026
Unspecified vulnerability in NEC WebSAM DeploymentManager 5.13 and earlier, as used in SigmaSystemCenter 2.1 Update2 and earlier, BladeSystemCenter, ExpressSystemCenter, and VirtualPCCenter 2.2 and earlier, allows remote attackers to cause a denial of service (OS shutdown or restart) via unknown vectors related to…
ModificadaAlta (9.3)20%💥 ExploitMicrosoft Outlook ExpressMicrosoft Windows Live MailMicrosoft Windows Mail12/5/201016/6/2026
Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows…
ModificadaMedia (4.3)1.7%—SUN Java System Communications Express1/4/201016/6/2026
Cross-site scripting (XSS) vulnerability in Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via the subject field of a message, as demonstrated by a subject containing an IMG element with a SRC attribute that performs a cross-site request forgery (CSRF)…
ModificadaMedia (5)1.2%—Apple Airport ExpressApple Airport ExtremeApple Time Capsule10/3/201016/6/2026
The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.
ModificadaAlta (7.5)52%💥 ExploitIBM Cognos Express5/2/201016/6/2026
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.
ModificadaAlta (7.2)0.43%—Intel Gm45 ChipsetIntel Pm45 Express ChipsetIntel Q35 ChipsetIntel Q43 Express Chipset+124/12/200916/6/2026
Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER…
ModificadaMedia (4.3)1.3%—Symantec Securityexpressions Audit AND Compliance Server15/10/200916/6/2026
Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue."
ModificadaBaja (3.5)1.0%—Symantec Securityexpressions Audit AND Compliance Server15/10/200916/6/2026
Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote authenticated users to inject arbitrary web script or HTML via "external client input" that triggers crafted error messages.
ModificadaAlta (9.3)23%—Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+2214/10/200916/6/2026
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office…
ModificadaAlta (9.3)20%—Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+2214/10/200916/6/2026
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
ModificadaAlta (9.3)21%—Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+2214/10/200916/6/2026
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio…
ModificadaAlta (9.3)22%—Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+2214/10/200916/6/2026
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer,…
ModificadaAlta (8.1)22%—Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+2214/10/200916/6/2026
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office…
ModificadaAlta (9.3)27%—Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+2214/10/200916/6/2026
Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel…
ModificadaAlta (9.3)24%—Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+2214/10/200916/6/2026
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office…
ModificadaAlta (7.6)5.5%—Cisco Unified Communications Manager ExpressCisco IOS28/9/200916/6/2026
Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.
ModificadaBaja (3.5)1.0%—Cisco CRSCisco Customer Response ApplicationsCisco IP QMCisco Unified CCX+216/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or HTML into the CCX database via unspecified vectors.
ModificadaAlta (9)2.4%—Cisco CRSCisco Customer Response ApplicationsCisco IP QMCisco Unified CCX+216/7/200916/6/2026
Directory traversal vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to read, modify, or delete arbitrary files via unspecified vectors.
ModificadaMedia (4.3)5.3%💥 ExploitSUN Java System Communications Express21/5/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book…
ModificadaAlta (7.2)52%💥 ExploitHP Data Protector Express14/5/200916/6/2026
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via…
ModificadaAlta (7.5)1.7%—IBM Tivoli Storage Manager ClientIBM Tivoli Storage Manager Express5/5/200916/6/2026
Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows attackers to read or modify arbitrary files via unknown vectors.
ModificadaAlta (10)3.3%—IBM Tivoli Storage Manager ClientIBM Tivoli Storage Manager Express5/5/200916/6/2026
Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified…
ModificadaAlta (10)71%💥 ExploitIBM Tivoli Storage Manager ClientIBM Tivoli Storage Manager Express5/5/200916/6/2026
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute…
ModificadaMedia (4.3)1.7%💥 ExploitExpressionengine26/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.
ModificadaMedia (4.3)1.7%—SUN Java System Communications Express12/3/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express allow remote attackers to inject arbitrary web script or HTML via the (1) Full Name or (2) Subject field.
Orbitaley — Vulnerabilidades