Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

746 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.6)1.7%—Cisco ASA 5500Cisco VPN 3000 Concentrator Series Software19/6/200616/6/2026
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en WebVPN en la serie Cisco VPN 3000 y concentradores Cisco ASA 5500 Series Adaptive Security Appliances (ASA), cuando se encuentra en el modo de WebVPN sin cliente, permite a atacantes remotos inyectar secuencias de comandos web o HTML a…
ModificadaMedia (4.3)2.3%💥 ExploitUbbcentral Ubb.threads2/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords.
ModificadaAlta (7.6)7.3%💥 ExploitZipcentral1/6/200616/6/2026
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.
ModificadaMedia (5.1)2.5%💥 ExploitUbbcentral Ubb.threads30/5/200616/6/2026
PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters.
ModificadaMedia (5.1)7.9%💥 ExploitUbbcentral Ubb.threads24/5/200616/6/2026
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.
ModificadaMedia (5)0.96%—Ubbcentral Ubb.threads28/3/200616/6/2026
SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter.
ModificadaAlta (7.5)1.3%💥 ExploitUbbcentral Ubb.threads4/2/200616/6/2026
SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter.
ModificadaAlta (7.8)3.2%—Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3030 Concentator31/1/200616/6/2026
Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet.
ModificadaAlta (7.5)2.6%—Cisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+1722/12/200516/6/2026
The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the…
ModificadaMedia (5)5.2%—Cisco Firewall Services ModuleCisco VPN 3000 Concentrator Series SoftwareCisco IOSCisco Adaptive Security Appliance Software+418/11/200516/6/2026
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details…
ModificadaAlta (7.5)5.6%—Symantec Veritas Storage ExecSymantec Veritas Storagecentral20/9/200516/6/2026
Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls.
ModificadaMedia (5)1.3%—Ubbcentral Ubb.threads29/6/200516/6/2026
Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter.
ModificadaMedia (6.5)0.96%—Ubbcentral Ubb.threads29/6/200516/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.
ModificadaAlta (7.5)1.2%💥 ExploitUbbcentral Ubb.threads29/6/200516/6/2026
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to…
ModificadaMedia (6.8)1.5%—Ubbcentral Ubb.threads29/6/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to…
ModificadaMedia (5)1.3%—Ubbcentral Ubb.threads29/6/200516/6/2026
Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.
ModificadaMedia (5)2.3%—Cisco VPN 3000 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+420/6/200516/6/2026
Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.
ModificadaMedia (4.3)0.94%—Centra2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields.
ModificadaAlta (7.5)1.2%—Ubbcentral Ubb.threads2/5/200516/6/2026
SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.
ModificadaMedia (5)1.6%—Cisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 Concentrator+430/3/200516/6/2026
Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.
ModificadaMedia (4.3)2.2%💥 ExploitUbbcentral Ubb.threads31/12/200416/6/2026
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary web script or HTML via the Cat parameter.
ModificadaMedia (4.3)3.9%💥 ExploitUbbcentral Ubb.threads31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter.
ModificadaAlta (7.5)2.4%💥 ExploitUbbcentral Ubb.threads21/10/200416/6/2026
SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.
ModificadaAlta (7.2)1.5%—Cluecentral Suexec.patch6/8/200416/6/2026
El programa modificado suexec de cPanel, cuando se configura para mod_php y compila para Apache 1.3.31 y anteriores sin mod_phpsuexec, permite a usuarios locales ejecutar scripts compartidos que no son de confianza y ganar privilegios, como se ha demostrado usando scripts como (1)proftpdvhosts or (2) addalink.cgi, una…
ModificadaMedia (5)2.1%—Cisco VPN 3015 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 ConcentratorCisco VPN 3080 Concentrator+227/5/200316/6/2026
Concentradores de Cisco de la serie VPN 3000 y Cisco VPN 3002 Hardware Client 2.x.x hasta 3.6.7A permiten que atacantes remotos causen una denegación de servicio (ralentización y posiblemente recarga) mediante una inundación con paquetes ICMP mal construídos.