Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.5% | — | Efrontlearning Efront Community ++ | 12/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter. | |
| Modificada | Media (5) | 17% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash." | |
| Modificada | Alta (9.3) | 17% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability." | |
| Modificada | Media (4.3) | 8.4% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability." | |
| Modificada | Media (4.3) | 8.3% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability." | |
| Modificada | Media (4.3) | 11% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response… | |
| Analizada | Crítica (9.8) | 49% | ⚠ Explotación activa | Microsoft Forefront Threat Management Gateway | 16/6/2011 | 16/6/2026 | The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability." | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Forefront Client SecurityMicrosoft Forefront Endpoint Protection 2010Microsoft Malicious Software Removal ToolMicrosoft Malware Protection Engine+3 | 25/2/2011 | 16/6/2026 | Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified… | |
| Modificada | Media (4.3) | 19% | — | Microsoft Forefront Unified Access Gateway | 10/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability." | |
| Modificada | Media (4.3) | 14% | — | Microsoft Forefront Unified Access Gateway | 10/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access… | |
| Modificada | Media (4.3) | 14% | — | Microsoft Forefront Unified Access Gateway | 10/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability." | |
| Modificada | Media (5.8) | 13% | — | Microsoft Forefront Unified Access Gateway | 10/11/2010 | 16/6/2026 | Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability." | |
| Modificada | Alta (7.5) | 1.2% | — | Efrontlearning Efront | 12/5/2010 | 16/6/2026 | SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter. | |
| Modificada | Media (6.8) | 5.0% | — | Efrontlearning Efront | 19/3/2010 | 16/6/2026 | Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter. | |
| Modificada | Alta (9.3) | 4.4% | — | Autodesk Alias Wavefront MayaAutodesk Maya | 24/11/2009 | 16/6/2026 | Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes." | |
| Modificada | Alta (9.3) | 23% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio… | |
| Modificada | Alta (9.3) | 22% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer,… | |
| Modificada | Alta (8.1) | 22% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office… | |
| Modificada | Alta (9.3) | 27% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel… | |
| Modificada | Alta (9.3) | 24% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office… | |
| Modificada | Media (6.8) | 1.9% | — | Efrontlearning Efront | 11/10/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the… | |
| Modificada | Media (6.8) | 4.7% | — | Efrontlearning Efront | 21/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/. | |
| Modificada | Media (4.3) | 23% | — | Microsoft Forefront Threat Management GatewayMicrosoft Internet Security AND Acceleration Server | 15/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to… |