Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

69 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.4%—Vignette Content Management6/3/200916/6/2026
Unspecified vulnerability in Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 allows "low privileged" users to gain administrator privileges via unknown attack vectors.
ModificadaMedia (6.9)0.39%—Geda Gnetlist18/11/200816/6/2026
sch2eaglepos.sh in geda-gnetlist 1.4.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file.
ModificadaMedia (6.4)0.87%—Airmagnet Enterprise6/11/200616/6/2026
The console in AirMagnet Enterprise before 7.5 build 6307 does not properly validate the Enterprise Server certificate, which allows remote attackers to read network traffic via a man-in-the-middle (MITM) attack, possibly related to the use of self-signed certificates.
ModificadaMedia (5)1.3%—Airmagnet Enterprise6/11/200616/6/2026
The AirMagnet Enterprise console and Remote Sensor console (Laptop) in AirMagnet Enterprise before 7.5 build 6307 allows remote attackers to inject arbitrary web script or HTML from a certain embedded Internet Explorer object into an SSID template value, aka "Cross-Application Scripting (XAS)".
ModificadaMedia (4.3)1.3%—Airmagnet Enterprise6/11/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AirMagnet Enterprise before 7.5 build 6307 allow remote attackers to inject arbitrary web script or HTML via (1) the 404 error page of the Smart Sensor Edge Sensor; (2) the user name for a failed logon, when displayed in the audit journals reviewing interface…
ModificadaMedia (5.1)18%💥 ExploitMagnet Bee-hive Lite27/6/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) header parameter to (a) conad/include/rootGui.inc.php and (b) include/rootGui.inc.php; (2) mysqlCall parameter to (c)…
ModificadaMedia (5)1.6%—Vignette Application Portal27/1/200516/6/2026
The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.
ModificadaMedia (5)1.5%—Vignette StoryserverVignette1/6/200416/6/2026
Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the output.
ModificadaAlta (7.5)7.6%—ROB Flynn GaimUltramagnetic3/3/200416/6/2026
Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login…
ModificadaAlta (7.5)8.5%—ROB Flynn GaimUltramagnetic3/3/200416/6/2026
Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.
ModificadaAlta (7.5)7.2%—ROB Flynn GaimUltramagnetic3/3/200416/6/2026
Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaMedia (6.4)1.6%—Vignette Content SuiteVignette StoryserverVignette2/7/200316/6/2026
Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.
ModificadaAlta (7.5)2.9%—Vignette Content SuiteVignette StoryserverVignette2/7/200316/6/2026
Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.
ModificadaMedia (4.3)2.0%💥 ExploitVignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.
ModificadaMedia (5)1.5%—Vignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.
ModificadaMedia (5)2.3%—Vignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template.
ModificadaMedia (5)1.6%—Vignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.
ModificadaAlta (7.5)2.5%—Vignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.
ModificadaMedia (5)3.5%💥 ExploitVignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.
Orbitaley — Vulnerabilidades