Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Vignette Content Management | 6/3/2009 | 16/6/2026 | Unspecified vulnerability in Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 allows "low privileged" users to gain administrator privileges via unknown attack vectors. | |
| Modificada | Media (6.9) | 0.39% | — | Geda Gnetlist | 18/11/2008 | 16/6/2026 | sch2eaglepos.sh in geda-gnetlist 1.4.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file. | |
| Modificada | Media (6.4) | 0.87% | — | Airmagnet Enterprise | 6/11/2006 | 16/6/2026 | The console in AirMagnet Enterprise before 7.5 build 6307 does not properly validate the Enterprise Server certificate, which allows remote attackers to read network traffic via a man-in-the-middle (MITM) attack, possibly related to the use of self-signed certificates. | |
| Modificada | Media (5) | 1.3% | — | Airmagnet Enterprise | 6/11/2006 | 16/6/2026 | The AirMagnet Enterprise console and Remote Sensor console (Laptop) in AirMagnet Enterprise before 7.5 build 6307 allows remote attackers to inject arbitrary web script or HTML from a certain embedded Internet Explorer object into an SSID template value, aka "Cross-Application Scripting (XAS)". | |
| Modificada | Media (4.3) | 1.3% | — | Airmagnet Enterprise | 6/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AirMagnet Enterprise before 7.5 build 6307 allow remote attackers to inject arbitrary web script or HTML via (1) the 404 error page of the Smart Sensor Edge Sensor; (2) the user name for a failed logon, when displayed in the audit journals reviewing interface… | |
| Modificada | Media (5.1) | 18% | 💥 Exploit | Magnet Bee-hive Lite | 27/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) header parameter to (a) conad/include/rootGui.inc.php and (b) include/rootGui.inc.php; (2) mysqlCall parameter to (c)… | |
| Modificada | Media (5) | 1.6% | — | Vignette Application Portal | 27/1/2005 | 16/6/2026 | The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag. | |
| Modificada | Media (5) | 1.5% | — | Vignette StoryserverVignette | 1/6/2004 | 16/6/2026 | Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the output. | |
| Modificada | Alta (7.5) | 7.6% | — | ROB Flynn GaimUltramagnetic | 3/3/2004 | 16/6/2026 | Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login… | |
| Modificada | Alta (7.5) | 8.5% | — | ROB Flynn GaimUltramagnetic | 3/3/2004 | 16/6/2026 | Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 7.2% | — | ROB Flynn GaimUltramagnetic | 3/3/2004 | 16/6/2026 | Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (6.4) | 1.6% | — | Vignette Content SuiteVignette StoryserverVignette | 2/7/2003 | 16/6/2026 | Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template. | |
| Modificada | Alta (7.5) | 2.9% | — | Vignette Content SuiteVignette StoryserverVignette | 2/7/2003 | 16/6/2026 | Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Vignette Content SuiteVignette StoryserverVignette | 30/6/2003 | 16/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template. | |
| Modificada | Media (5) | 1.5% | — | Vignette Content SuiteVignette StoryserverVignette | 30/6/2003 | 16/6/2026 | The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks. | |
| Modificada | Media (5) | 2.3% | — | Vignette Content SuiteVignette StoryserverVignette | 30/6/2003 | 16/6/2026 | Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template. | |
| Modificada | Media (5) | 1.6% | — | Vignette Content SuiteVignette StoryserverVignette | 30/6/2003 | 16/6/2026 | Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command. | |
| Modificada | Alta (7.5) | 2.5% | — | Vignette Content SuiteVignette StoryserverVignette | 30/6/2003 | 16/6/2026 | Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Vignette Content SuiteVignette StoryserverVignette | 30/6/2003 | 16/6/2026 | Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports. |