Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%💥 ExploitJoomtraders COM Allcinevid20/1/201116/6/2026
SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
ModificadaAlta (7.8)3.0%💥 ExploitCamtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-20017/11/201016/6/2026
The web server on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to cause a denial of service (device reboot) via a large number of requests in a short time interval.
ModificadaAlta (10)9.4%💥 ExploitCamtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-20017/11/201016/6/2026
The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a default password of m for the root account, and a default password of merlin for the mg3500 account, which makes it easier for remote attackers to obtain access via the TELNET…
ModificadaAlta (10)4.2%💥 ExploitCamtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-20017/11/201016/6/2026
The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to bypass authentication via a // (slash slash) at the beginning of a URI, as demonstrated by the //system.html URI.
ModificadaAlta (7.8)16%💥 ExploitCamtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-20017/11/201016/6/2026
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
ModificadaAlta (9.3)5.6%💥 ExploitCamtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-20017/11/201016/6/2026
Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to execute arbitrary code via a long string in the first argument to the connect method.
ModificadaMedia (4.3)1.5%💥 ExploitComtrend Ct-507it Adsl Router2/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter.
ModificadaAlta (7.5)1.1%💥 ExploitCOM Joomtracker6/2/200916/6/2026
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php.
ModificadaMedia (6.8)4.7%—Matt Kimball AND Roger Wolff MTR21/5/200816/6/2026
Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the ns_name_ntop function in resolv/ns_name.c…
ModificadaAlta (7.8)1.5%—BEA Systems Aqualogic InteractionBEA Systems Plumtree Collaboration22/2/200816/6/2026
Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL.
ModificadaMedia (4.3)1.2%—BEA Systems Aqualogic InteractionBEA Systems Plumtree Foundation21/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
ModificadaMedia (5)1.4%—Cgi-club Imtrset5/7/200516/6/2026
im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.
ModificadaMedia (4.6)0.33%—MTR10/1/200516/6/2026
Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.
ModificadaMedia (5.8)2.2%💥 ExploitSerena Software Serena Teamtrack31/12/200416/6/2026
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.
ModificadaBaja (2.1)0.50%—MTR12/8/200216/6/2026
Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable.
ModificadaAlta (7.5)1.6%—Plumtree Corporate Portal16/5/200216/6/2026
Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter.
ModificadaAlta (7.2)0.82%💥 ExploitMatt Kimball AND Roger Wolff MTRTurbolinux3/3/200016/6/2026
The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.
ModificadaMedia (5)5.8%💥 ExploitTeamshare Teamtrack1/10/199916/6/2026
TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Orbitaley — Vulnerabilidades