Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | Mercator Sentinel | 22/9/2011 | 16/6/2026 | SQL injection vulnerability in the login form in the web interface in Mercator SENTINEL 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Opencosmo Visualsentinel | 7/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Opencosmo VisualSentinel 0.7 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header ($_SERVER ['HTTP_USER_AGENT']), which is not properly handled when displaying log files. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Safenet Sentinel Keys ServerSafenet Sentinel Protection Server | 13/2/2008 | 16/6/2026 | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Evilsentinel | 18/1/2008 | 16/6/2026 | admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Evilsentinel | 18/1/2008 | 16/6/2026 | admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php. | |
| Modificada | Media (5) | 10% | 💥 Exploit | Safenet Sentinel Keys ServerSafenet Sentinel Protection Server | 20/12/2007 | 16/6/2026 | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string. | |
| Modificada | Alta (7.5) | 1.1% | — | Nukescripts Nukesentinel | 1/10/2007 | 16/6/2026 | SQL injection vulnerability in the abget_admin function in includes/nukesentinel.php in NukeSentinel 2.5.12 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie. | |
| Modificada | Alta (7.5) | 1.1% | — | Nukescripts Nukesentinel | 1/10/2007 | 16/6/2026 | SQL injection vulnerability in the is_god function in includes/nukesentinel.php in NukeSentinel 2.5.11 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie, a different vector than CVE-2007-5125. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Nukescripts Nukesentinel | 16/3/2007 | 16/6/2026 | nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172. | |
| Modificada | Media (6.8) | 1.0% | — | Nukescripts Nukesentinel | 16/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NukeSentinel before 2.5.06 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "filters for https:// and http://". | |
| Modificada | Media (6.4) | 1.1% | 💥 Exploit | Nukescripts Nukesentinel | 2/3/2007 | 16/6/2026 | SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit." | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Nukescripts Nukesentinel | 2/3/2007 | 16/6/2026 | SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie. | |
| Modificada | Alta (10) | 71% | 💥 Exploit | Safenet Sentinel License Manager | 2/5/2005 | 16/6/2026 | Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093. |