Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Philippine Long Distance Telephone Speedsurf 504an FirmwarePhilippine Long Distance Telephone Kasda Kw58293 Firmware | 21/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script or HTML via the ssid parameter. | |
| Modificada | Media (6.8) | 0.66% | — | Philippine Long Distance Telephone Speedsurf 504an FirmwarePhilippine Long Distance Telephone Kasda Kw58293 Firmware | 21/9/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to hijack the authentication of administrators for requests that perform setup… | |
| Modificada | Media (6.8) | 10% | 💥 Exploit | KTH Snack Sound ToolkitKTH WavesurferOpensuse | 28/10/2013 | 16/6/2026 | Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file. | |
| Modificada | Alta (7.5) | 2.1% | — | Drusus LogsurferKerry Thompson Logsurfer+ | 27/1/2012 | 16/6/2026 | Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote attackers to execute arbitrary commands via crafted strings in a log file. | |
| Modificada | Media (5) | 8.6% | 💥 Exploit | Motorola Surfboard Sbv6120e | 16/6/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request. | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | IF Surfalert Project IF Surfalert | 4/5/2010 | 16/6/2026 | Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Media (4.3) | 0.87% | — | Surfstats | 5/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue. | |
| Modificada | Media (4.3) | 1.1% | — | Ljscripts Auto-surf Traffic Exchange Script | 30/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary web script or HTML via the rid parameter to (1) index.php, (2) faq.php, and (3) register.php. | |
| Modificada | Alta (7.8) | 1.5% | — | Motorola Surfboard | 28/4/2008 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html, and (2) cause a denial of service (hard… | |
| Modificada | Alta (7.8) | 1.4% | — | Gosurf Browser | 9/2/2007 | 16/6/2026 | Cross-domain vulnerability in GoSuRF Browser 2.62 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that… | |
| Modificada | Alta (7.8) | 7.8% | 💥 Exploit | Motorola Surfboard | 10/10/2006 | 16/6/2026 | The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter. | |
| Modificada | Media (5) | 1.4% | — | Finjan Software Surfingate | 14/6/2005 | 16/6/2026 | Finjan SurfinGate 7.0SP2 and SP3 allows remote attackers to download blocked files via hex-encoded characters in a filename, as demonstrated using "%2e". | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Finjan Software Surfingate | 31/12/2004 | 16/6/2026 | Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy… | |
| Modificada | Media (4.3) | 1.2% | — | Xperience Sandsurfer | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified Perl scripts in SandSurfer before 1.7.1 allow remote attackers to inject arbitrary web script or HTML, which is later executed by a target who views reports containing the injected data. | |
| Modificada | Media (4.6) | 0.40% | — | Info Touch Surfnet | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Loom Software Surfnow ProfessionalLoom Software Surfnow Standard | 31/12/2004 | 16/6/2026 | SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow. | |
| Modificada | Media (4.6) | 0.69% | 💥 Exploit | Info Touch Surfnet | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command. | |
| Modificada | Baja (2.1) | 0.32% | — | Info Touch Surfnet KioskAI | 31/12/2004 | 16/6/2026 | Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI. | |
| Modificada | Alta (7.5) | 2.5% | — | Snapfiles Whisper FTP Surfer | 27/7/2004 | 16/6/2026 | Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename. | |
| Modificada | Alta (7.5) | 1.8% | — | Sandsurfer | 8/2/2004 | 16/6/2026 | Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user. | |
| Modificada | Media (4.3) | 3.2% | — | ISC BindNixu NamesurferCompaq Tru64Freebsd+6 | 15/12/2003 | 16/6/2026 | ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value. | |
| Modificada | Media (5) | 2.6% | — | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter. | |
| Modificada | Media (5) | 2.6% | — | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it. |