Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.1% | — | IBM Filenet Content Manager | 13/9/2010 | 16/6/2026 | IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 places a session token in the URI, which might allow remote attackers to obtain sensitive information by reading a Referer log file. | |
| Modificada | Media (5) | 1.2% | — | IBM Filenet Content Manager | 13/9/2010 | 16/6/2026 | IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 transmits passwords in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (4.3) | 1.0% | — | IBM Filenet Content Manager | 13/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 0.91% | — | IBM Filenet Content Manager | 28/7/2010 | 16/6/2026 | IBM FileNet Content Manager (CM) 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4 does not properly manage the InheritParentPermissions setting during an upgrade from 3.x, which might allow attackers to bypass intended folder permissions via unspecified vectors. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Creasito E-commerce Content Manager | 12/7/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | The-ghost AR WEB Content Manager | 23/3/2010 | 16/6/2026 | AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php. | |
| Modificada | Alta (10) | 2.3% | — | IBM DB2 Content Manager | 23/3/2010 | 16/6/2026 | Unspecified vulnerability in the single sign-on functionality in the Web Services implementation in IBM DB2 Content Manager (CM) Toolkit 8.3 before FP13 on z/OS and DB2 Information Integrator for Content 8.3 before FP13 has unknown impact and remote attack vectors. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Michael J Greenwood PHP Content Manager | 28/10/2009 | 16/6/2026 | Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content_path parameter. | |
| Modificada | Media (4.3) | 2.4% | — | Broadcom Anti-virusBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti-virus SDKBroadcom Common Services+29 | 13/10/2009 | 16/6/2026 | Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to… | |
| Modificada | Alta (9.3) | 7.6% | — | Broadcom Anti-virusBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti-virus SDKBroadcom Common Services+28 | 13/10/2009 | 16/6/2026 | Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to… | |
| Modificada | Media (6.8) | 4.1% | 💥 Exploit | The-ghost AR WEB Content Manager | 16/9/2009 | 16/6/2026 | Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | The-ghost AR WEB Content Manager | 16/9/2009 | 16/6/2026 | SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (4.6) | 0.95% | — | IBM Filenet Content Manager | 8/6/2009 | 16/6/2026 | IBM FileNet Content Manager 4.0, 4.0.1, and 4.5, as used in IBM WebSphere Application Server (WAS) and Oracle BEA WebLogic Application Server, when the CE Web Services listener has a certain WSEAF configuration, does not properly restrict use of a cached Subject, which allows remote attackers to obtain access with the… | |
| Modificada | Alta (10) | 1.5% | — | IBM DB2 Content Manager | 2/4/2009 | 16/6/2026 | Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack vectors. | |
| Modificada | Alta (10) | 4.3% | — | Broadcom Anti-spywareBroadcom Anti-spyware FOR THE EnterpriseBroadcom Anti-virusBroadcom Anti-virus FOR THE Enterprise+15 | 28/1/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a… | |
| Modificada | Alta (10) | 10% | — | CA Etrust Secure Content Manager | 4/6/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories,… | |
| Modificada | Alta (7.8) | 3.2% | — | Broadcom Secure Content Manager | 27/4/2008 | 16/6/2026 | The eTrust Common Services (Transport) Daemon (eCSqdmn) in CA Secure Content Manager 8.0.28000.511 and earlier allows remote attackers to cause a denial of service (crash or CPU consumption) via a malformed packet to TCP port 1882. | |
| Modificada | Alta (10) | 1.8% | — | IBM DB2 Content Manager | 4/4/2008 | 16/6/2026 | Unspecified vulnerability in IBM DB2 Content Manager before 8.3 FP8 has unknown impact and attack vectors related to the AllowedTrustedLogin privilege. | |
| Modificada | Media (4.3) | 1.0% | — | Besavvy Savvy Content Manager | 12/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Savvy Content Manager (CM) allow remote attackers to inject arbitrary web script or HTML via the searchterms parameter to (1) searchresults.cfm, (2) search_results.cfm, and (3) search_results/index.cfm. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Alta (10) | 1.8% | — | IBM DB2 Content Manager Toolkit | 27/12/2007 | 16/6/2026 | Unspecified vulnerability in eClient in IBM DB2 Content Manager (CM) Toolkit 8.3 before fix pack 7 for z/OS has unknown impact and attack vectors, related to "scripting." | |
| Modificada | Media (4.3) | 3.6% | — | Broadcom Anti-spywareBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti Virus SDKBroadcom Antispyware FOR THE Enterprise+19 | 26/7/2007 | 16/6/2026 | arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | CA Etrust Secure Content ManagerIngres Database Server | 21/6/2007 | 16/6/2026 | Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Database Server 3.0.3, as used in CA (Computer Associates) products including eTrust Secure Content Manager r8 on Windows, allow remote attackers to execute arbitrary code via… | |
| Modificada | Alta (9.3) | 50% | 💥 Exploit | Broadcom Anti-virus FOR THE EnterpriseBroadcom Brightstor Arcserve BackupBroadcom Common ServicesBroadcom Etrust Antivirus+9 | 6/6/2007 | 16/6/2026 | Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file. | |
| Modificada | Media (6.8) | 1.2% | — | Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB ClientHitachi Ucosminexus Collaboration Portal+1 | 31/3/2007 | 16/6/2026 | SQL injection vulnerability in Hitachi Collaboration - Online Community Management 01-00 through 01-30, as used in Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, and uCosminexus Content Manager, allows remote attackers to execute… | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Creasito E-commerce Content Manager | 7/11/2006 | 16/6/2026 | Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged functions via a non-empty finame parameter to (1) addnewcont.php, (2) adminpassw.php, (3) amministrazione.php, (4) artins.php, (5) bgcolor.php, (6) cancartcat.php, (7) canccat.php, (8) cancelart.php, (9)… |