Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Pgpooladmin | 9/1/2019 | 17/6/2026 | PgpoolAdmin 4.0 and earlier allows remote attackers to bypass the login authentication and obtain the administrative privilege of the PostgreSQL database via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Pooledwebsocket Project Pooledwebsocket | 7/6/2018 | 17/6/2026 | pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 77% | — | Nanopool Claymore Dual Miner | 9/2/2018 | 17/6/2026 | Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write mode enabled. | |
| Modificada | Media (5) | 1.4% | — | SAP Transaction Data Pool | 9/6/2014 | 17/6/2026 | SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | Disk Pool Manager Project Disk Pool Manager | 13/5/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in LCG Disk Pool Manager (DPM) before 1.8.6, as used in EGI UDM, allow remote attackers to execute arbitrary SQL commands via the (1) r_token variable in the dpm_get_pending_req_by_token, (2) dpm_get_cpr_by_fullid, (3) dpm_get_cpr_by_surl, (4) dpm_get_cpr_by_surls, (5)… | |
| Modificada | Media (5) | 3.9% | — | Boost Pool | 25/7/2012 | 16/6/2026 | Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected. | |
| Modificada | Media (5) | 2.2% | — | Brainjar ASP Football Pool | 27/7/2009 | 16/6/2026 | ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for NFL.mdb. | |
| Modificada | Media (4.3) | 3.8% | — | Wordpress Pool | 22/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in the Pool 1.0.7 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). | |
| Modificada | Media (6.8) | 5.8% | — | Joomla Tour DE France Pool | 8/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Xoops Pool Module | 13/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment. | |
| Modificada | Media (5) | 2.3% | — | Php-nuke News ModulePhp-nuke Pool Module | 12/1/2006 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag. | |
| Modificada | Alta (7.5) | 1.2% | — | TMC Visionpool Mercury CMS | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (4.3) | 0.94% | — | TMC Visionpool Mercury CMS | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters. | |
| Modificada | Media (4.6) | 1.1% | — | Thepoolclub IpoolThepoolclub Isnooker | 2/5/2005 | 16/6/2026 | ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges. |