Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.35% | — | Ininet Solutions Scada WEB Server | 25/10/2015 | 17/6/2026 | IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | Ininet Solutions Scada WEB Server | 25/10/2015 | 17/6/2026 | Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname. | |
| Modificada | Media (6.4) | 1.4% | — | Ininet Solutions Scada WEB Server | 25/10/2015 | 17/6/2026 | IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string. | |
| Modificada | Alta (10) | 4.1% | — | Ininet Solutions Scada WEB Server | 25/10/2015 | 17/6/2026 | Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request. | |
| Modificada | Media (6.4) | 2.7% | — | Uninett MOD Auth MellonOracle Linux | 15/11/2014 | 17/6/2026 | The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory." | |
| Modificada | Alta (9.4) | 3.6% | — | Uninett MOD Auth MellonRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 14/11/2014 | 17/6/2026 | The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data. | |
| Modificada | Media (5.4) | 0.27% | — | Sudaninet | 16/10/2014 | 17/6/2026 | The SudaniNet (aka com.sudaninet.wtwqiqbegq_btwlda) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.4) | 1.5% | — | Uninett Radsecproxy | 20/11/2012 | 16/6/2026 | The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a… | |
| Modificada | Media (6.4) | 1.8% | — | Uninett Radsecproxy | 20/11/2012 | 16/6/2026 | radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients. | |
| Modificada | Alta (7.5) | 8.5% | 💥 Exploit | Venture Nine Tagger LE | 14/9/2006 | 16/6/2026 | Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, and (3) admin/index.php. | |
| Modificada | Media (5.1) | 1.3% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters. | |
| Modificada | Alta (7.5) | 1.9% | — | Tomi Manninen Linuxnode | 20/10/2003 | 16/6/2026 | Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code. | |
| Modificada | Alta (7.5) | 2.4% | — | Tomi Manninen Linuxnode | 20/10/2003 | 16/6/2026 | Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 1.2% | — | Uninet Statsplus | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers. |