Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.32%—IBM General Parallel File System Storage ServerIBM Spectrum Scale29/6/201617/6/2026
IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command.
ModificadaAlta (8.4)0.50%—IBM Elastic Storage ServerIBM General Parallel File System Storage Server19/6/201617/6/2026
IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program.
ModificadaMedia (4.3)1.5%—Oracle General Ledger21/1/201617/6/2026
Unspecified vulnerability in the Oracle General Ledger component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Consolidation Hierarchy Viewer.
ModificadaMedia (4)0.36%—IBM General Parallel File SystemIBM Spectrum Scale2/1/201617/6/2026
IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors.
ModificadaBaja (2.1)0.38%—IBM General Parallel File SystemIBM Spectrum Scale26/10/201517/6/2026
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.
ModificadaAlta (7.2)0.58%—IBM General Parallel File SystemIBM Spectrum Scale26/10/201517/6/2026
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.
ModificadaBaja (3.5)0.97%—IBM General Parallel File System6/4/201517/6/2026
/usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive to detect included keys, which might allow remote attackers to obtain sensitive information by leveraging access to a…
ModificadaMedia (4.9)0.39%—IBM General Parallel File System24/3/201517/6/2026
The mmfslinux kernel module in IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to cause a denial of service (memory corruption) via unspecified character-device ioctl calls.
ModificadaAlta (10)4.2%—IBM General Parallel File System24/3/201517/6/2026
IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspecified vectors.
ModificadaAlta (7.2)0.45%—IBM General Parallel File System24/3/201517/6/2026
IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges for program execution via unspecified vectors.
ModificadaMedia (4)1.2%—IBM General Parallel File System4/2/201417/6/2026
IBM General Parallel File System (GPFS) 3.4 through 3.4.0.27 and 3.5 through 3.5.0.16 allows attackers to cause a denial of service (daemon crash) via crafted arguments to a setuid program.
ModificadaMedia (6.8)2.9%—Squirrelmail Imap General.phpSquirrelmail22/5/200916/6/2026
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue…
ModificadaMedia (6.8)0.85%💥 ExploitMatthew General RSS Simple News27/2/200916/6/2026
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the pid parameter.
ModificadaAlta (7.5)1.4%—Warhound General Shopping Cart1/12/200616/6/2026
SQL injection vulnerability in item.asp in WarHound General Shopping Cart allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
ModificadaAlta (7.5)1.5%—Activecampaign 1-2-allActivecampaign GeneralActivecampaign IsalientActivecampaign Knowledgebuilder+23/3/200616/6/2026
PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.
ModificadaAlta (10)29%💥 ExploitData General DG UXISC BindSGI IrixBsdi BSD OS+98/4/199816/6/2026
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
ModificadaMedia (5)2.4%—Data General DG UXISC BindIBM AIXNEC ASL UX 4800+78/4/199816/6/2026
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
ModificadaMedia (5.4)5.5%—Data General DG UXISC BindIBM AIXNEC ASL UX 4800+78/4/199816/6/2026
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
ModificadaAlta (7.5)2.0%—Network General Netxray18/2/199816/6/2026
Buffer overflow in web-admin tool in NetXRay 2.6 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.
ModificadaAlta (7.5)4.1%—Data General DG UX11/8/199716/6/2026
The DG/UX finger daemon allows remote command execution through shell metacharacters.
ModificadaAlta (8.4)1.3%💥 ExploitData General DG UXSGI IrixBsdi BSD OSDebian Linux+426/4/199716/6/2026
Buffer overflow in xlock program allows local users to execute commands as root.
ModificadaMedia (5)1.7%—Data General DG UXNCR Mp-rasSGI IrixIBM AIX+624/4/199616/6/2026
Delete or create a file via rpc.statd, due to invalid information.
Orbitaley — Vulnerabilidades