Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

65 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.35%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.
ModificadaMedia (5)2.1%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.
ModificadaMedia (6.4)1.4%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string.
ModificadaAlta (10)4.1%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request.
ModificadaMedia (6.4)2.7%—Uninett MOD Auth MellonOracle Linux15/11/201417/6/2026
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
ModificadaAlta (9.4)3.6%—Uninett MOD Auth MellonRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+314/11/201417/6/2026
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
ModificadaMedia (5.4)0.27%—Sudaninet16/10/201417/6/2026
The SudaniNet (aka com.sudaninet.wtwqiqbegq_btwlda) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.4)1.5%—Uninett Radsecproxy20/11/201216/6/2026
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a…
ModificadaMedia (6.4)1.8%—Uninett Radsecproxy20/11/201216/6/2026
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.
ModificadaAlta (7.5)8.5%💥 ExploitVenture Nine Tagger LE14/9/200616/6/2026
Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, and (3) admin/index.php.
ModificadaMedia (5.1)1.3%—Cloudnine Interactive Links Manager24/8/200616/6/2026
SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.
ModificadaMedia (6.8)1.6%—Cloudnine Interactive Links Manager24/8/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters.
ModificadaAlta (7.5)1.9%—Tomi Manninen Linuxnode20/10/200316/6/2026
Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.
ModificadaAlta (7.5)2.4%—Tomi Manninen Linuxnode20/10/200316/6/2026
Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.
ModificadaMedia (5)1.2%—Uninet Statsplus31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.
Orbitaley — Vulnerabilidades