Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.32% | — | IBM General Parallel File System Storage ServerIBM Spectrum Scale | 29/6/2016 | 17/6/2026 | IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command. | |
| Modificada | Alta (8.4) | 0.50% | — | IBM Elastic Storage ServerIBM General Parallel File System Storage Server | 19/6/2016 | 17/6/2026 | IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program. | |
| Modificada | Media (4.3) | 1.5% | — | Oracle General Ledger | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle General Ledger component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Consolidation Hierarchy Viewer. | |
| Modificada | Media (4) | 0.36% | — | IBM General Parallel File SystemIBM Spectrum Scale | 2/1/2016 | 17/6/2026 | IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.38% | — | IBM General Parallel File SystemIBM Spectrum Scale | 26/10/2015 | 17/6/2026 | IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.58% | — | IBM General Parallel File SystemIBM Spectrum Scale | 26/10/2015 | 17/6/2026 | IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.97% | — | IBM General Parallel File System | 6/4/2015 | 17/6/2026 | /usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive to detect included keys, which might allow remote attackers to obtain sensitive information by leveraging access to a… | |
| Modificada | Media (4.9) | 0.39% | — | IBM General Parallel File System | 24/3/2015 | 17/6/2026 | The mmfslinux kernel module in IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to cause a denial of service (memory corruption) via unspecified character-device ioctl calls. | |
| Modificada | Alta (10) | 4.2% | — | IBM General Parallel File System | 24/3/2015 | 17/6/2026 | IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.45% | — | IBM General Parallel File System | 24/3/2015 | 17/6/2026 | IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges for program execution via unspecified vectors. | |
| Modificada | Media (4) | 1.2% | — | IBM General Parallel File System | 4/2/2014 | 17/6/2026 | IBM General Parallel File System (GPFS) 3.4 through 3.4.0.27 and 3.5 through 3.5.0.16 allows attackers to cause a denial of service (daemon crash) via crafted arguments to a setuid program. | |
| Modificada | Media (6.8) | 2.9% | — | Squirrelmail Imap General.phpSquirrelmail | 22/5/2009 | 16/6/2026 | The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue… | |
| Modificada | Media (6.8) | 0.85% | 💥 Exploit | Matthew General RSS Simple News | 27/2/2009 | 16/6/2026 | SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the pid parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Warhound General Shopping Cart | 1/12/2006 | 16/6/2026 | SQL injection vulnerability in item.asp in WarHound General Shopping Cart allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Activecampaign 1-2-allActivecampaign GeneralActivecampaign IsalientActivecampaign Knowledgebuilder+2 | 3/3/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter. | |
| Modificada | Alta (10) | 29% | 💥 Exploit | Data General DG UXISC BindSGI IrixBsdi BSD OS+9 | 8/4/1998 | 16/6/2026 | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. | |
| Modificada | Media (5) | 2.4% | — | Data General DG UXISC BindIBM AIXNEC ASL UX 4800+7 | 8/4/1998 | 16/6/2026 | Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. | |
| Modificada | Media (5.4) | 5.5% | — | Data General DG UXISC BindIBM AIXNEC ASL UX 4800+7 | 8/4/1998 | 16/6/2026 | Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer. | |
| Modificada | Alta (7.5) | 2.0% | — | Network General Netxray | 18/2/1998 | 16/6/2026 | Buffer overflow in web-admin tool in NetXRay 2.6 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request. | |
| Modificada | Alta (7.5) | 4.1% | — | Data General DG UX | 11/8/1997 | 16/6/2026 | The DG/UX finger daemon allows remote command execution through shell metacharacters. | |
| Modificada | Alta (8.4) | 1.3% | 💥 Exploit | Data General DG UXSGI IrixBsdi BSD OSDebian Linux+4 | 26/4/1997 | 16/6/2026 | Buffer overflow in xlock program allows local users to execute commands as root. | |
| Modificada | Media (5) | 1.7% | — | Data General DG UXNCR Mp-rasSGI IrixIBM AIX+6 | 24/4/1996 | 16/6/2026 | Delete or create a file via rpc.statd, due to invalid information. |