Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

67 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)3.2%—Gleamtech Filevista2/12/201417/6/2026
GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in a zip archive, which is not properly handled during extraction.
ModificadaMedia (4)1.8%—Gleamtech Filevista2/12/201417/6/2026
GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when saving a zip file, which reveals the installation path in an error message.
ModificadaAlta (7.8)2.6%💥 ExploitSamsung Ps50c7700 Television FirmwareSamsung Ps50c7700 Television23/7/201316/6/2026
The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon crash) via a long URI to TCP port 5600.
ModificadaAlta (10)1.4%—Youmail Visual Voicemail Plus7/3/201216/6/2026
Unspecified vulnerability in the YouMail Visual Voicemail Plus (com.youmail.android.vvm) application 2.0.45 and 2.1.43 for Android has unknown impact and attack vectors.
ModificadaAlta (7.2)1.5%—Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+3113/4/201116/6/2026
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different…
ModificadaAlta (7.5)2.3%—Polyvision Roomwizard FirmwarePolyvision Roomwizard12/1/201116/6/2026
The PolyVision RoomWizard with firmware 3.2.3 has a default password of roomwizard for the administrator account, which makes it easier for remote attackers to obtain console access via an HTTP session, a different vulnerability than CVE-2010-0214.
ModificadaMedia (5)1.9%—Polyvision Roomwizard FirmwarePolyvision Roomwizard12/1/201116/6/2026
The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the…
ModificadaMedia (5.4)0.88%—Clavister Coreplus16/7/200716/6/2026
The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allows remote attackers to cause a denial of service (gateway stop) via certain certificates.
ModificadaMedia (5)1.9%—Clavister Coreplus16/7/200716/6/2026
The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files.
ModificadaAlta (10)2.3%—Clavister Coreplus16/7/200716/6/2026
The SMTP ALG in Clavister CorePlus before 8.80.04, and 8.81.00, does not properly parse SMTP commands in certain circumstances, which allows remote attackers to bypass address blacklists.
ModificadaMedia (4.3)1.8%—Astalavista IT Engineering Contrexx19/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).
ModificadaAlta (7.5)2.8%—Clavister FirewallClavister Security Gateway30/11/200516/6/2026
The Internet Key Exchange version 1 (IKEv1) implementation in Clavister Client Web allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear…
ModificadaMedia (5)1.8%—Astalavista IT Engineering Contrexx3/8/200516/6/2026
Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.
ModificadaAlta (7.5)1.6%—Astalavista IT Engineering Contrexx3/8/200516/6/2026
Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.
ModificadaMedia (4.3)1.8%—Astalavista IT Engineering Contrexx3/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.
ModificadaAlta (7.2)1.1%💥 ExploitTridia Doublevision14/11/200016/6/2026
Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument.
ModificadaMedia (5)1.7%—Virtual Vision FTP Browser12/7/200016/6/2026
ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack.
Orbitaley — Vulnerabilidades