Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.38% | — | EMC Data Protection Advisor CollectorOracle Solaris Sparc | 28/3/2011 | 16/6/2026 | EMC Data Protection Advisor Collector 5.7 and 5.7.1 on Solaris SPARC platforms uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. | |
| Modificada | Alta (7.5) | 0.91% | — | Phparcadescript | 14/8/2009 | 16/6/2026 | SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 2.2% | — | SUN Sparc Enterprise Server | 16/1/2009 | 16/6/2026 | The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root password, perform a root login to the eXtended System Control Facility Unit (aka XSCFU or Service Processor), and have unspecified other impact. | |
| Modificada | Media (4.6) | 0.31% | — | SUN Blade T6300 ServerSUN Blade T6320 ServerSUN Fire Enterprise Server T1000SUN Fire Enterprise Server T2000+9 | 7/11/2008 | 16/6/2026 | The SPARC hypervisor in Sun System Firmware 6.6.3 through 6.6.5 and 7.1.3 through 7.1.3.e on UltraSPARC T1, T2, and T2+ processors allows logical domain users to access memory in other logical domains via unknown vectors. | |
| Modificada | Alta (9) | 2.0% | — | SUN Integrated Lights-out ManagerSUN Blade 6000 Modular System With ChassisSUN Blade 6048 Modular System With ChassisSUN Blade 8000 Modular System+33 | 23/10/2008 | 16/6/2026 | Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Phparcadescript | 19/8/2008 | 16/6/2026 | SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action. | |
| Modificada | Alta (7.5) | 0.93% | — | Phparcadescript | 5/3/2008 | 16/6/2026 | SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action. | |
| Modificada | Media (4.3) | 1.9% | — | Phparcadescript | 9/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the submissionstatus parameter in index.php, the (4)… | |
| Modificada | Alta (7.2) | 1.5% | — | ISC INNNetscape News ServerSUN SparcRedhat Linux+2 | 20/2/1997 | 16/6/2026 | ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN. |