Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.2% | — | Gleamtech Filevista | 2/12/2014 | 17/6/2026 | GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in a zip archive, which is not properly handled during extraction. | |
| Modificada | Media (4) | 1.8% | — | Gleamtech Filevista | 2/12/2014 | 17/6/2026 | GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when saving a zip file, which reveals the installation path in an error message. | |
| Modificada | Alta (7.8) | 2.6% | 💥 Exploit | Samsung Ps50c7700 Television FirmwareSamsung Ps50c7700 Television | 23/7/2013 | 16/6/2026 | The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon crash) via a long URI to TCP port 5600. | |
| Modificada | Alta (10) | 1.4% | — | Youmail Visual Voicemail Plus | 7/3/2012 | 16/6/2026 | Unspecified vulnerability in the YouMail Visual Voicemail Plus (com.youmail.android.vvm) application 2.0.45 and 2.1.43 for Android has unknown impact and attack vectors. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Alta (7.5) | 2.3% | — | Polyvision Roomwizard FirmwarePolyvision Roomwizard | 12/1/2011 | 16/6/2026 | The PolyVision RoomWizard with firmware 3.2.3 has a default password of roomwizard for the administrator account, which makes it easier for remote attackers to obtain console access via an HTTP session, a different vulnerability than CVE-2010-0214. | |
| Modificada | Media (5) | 1.9% | — | Polyvision Roomwizard FirmwarePolyvision Roomwizard | 12/1/2011 | 16/6/2026 | The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the… | |
| Modificada | Media (5.4) | 0.88% | — | Clavister Coreplus | 16/7/2007 | 16/6/2026 | The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allows remote attackers to cause a denial of service (gateway stop) via certain certificates. | |
| Modificada | Media (5) | 1.9% | — | Clavister Coreplus | 16/7/2007 | 16/6/2026 | The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files. | |
| Modificada | Alta (10) | 2.3% | — | Clavister Coreplus | 16/7/2007 | 16/6/2026 | The SMTP ALG in Clavister CorePlus before 8.80.04, and 8.81.00, does not properly parse SMTP commands in certain circumstances, which allows remote attackers to bypass address blacklists. | |
| Modificada | Media (4.3) | 1.8% | — | Astalavista IT Engineering Contrexx | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF). | |
| Modificada | Alta (7.5) | 2.8% | — | Clavister FirewallClavister Security Gateway | 30/11/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation in Clavister Client Web allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear… | |
| Modificada | Media (5) | 1.8% | — | Astalavista IT Engineering Contrexx | 3/8/2005 | 16/6/2026 | Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml. | |
| Modificada | Alta (7.5) | 1.6% | — | Astalavista IT Engineering Contrexx | 3/8/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module. | |
| Modificada | Media (4.3) | 1.8% | — | Astalavista IT Engineering Contrexx | 3/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module. | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | Tridia Doublevision | 14/11/2000 | 16/6/2026 | Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument. | |
| Modificada | Media (5) | 1.7% | — | Virtual Vision FTP Browser | 12/7/2000 | 16/6/2026 | ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack. |