Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

90 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.2%—Philippine Long Distance Telephone Speedsurf 504an FirmwarePhilippine Long Distance Telephone Kasda Kw58293 Firmware21/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script or HTML via the ssid parameter.
ModificadaMedia (6.8)0.66%—Philippine Long Distance Telephone Speedsurf 504an FirmwarePhilippine Long Distance Telephone Kasda Kw58293 Firmware21/9/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to hijack the authentication of administrators for requests that perform setup…
ModificadaMedia (6.8)10%💥 ExploitKTH Snack Sound ToolkitKTH WavesurferOpensuse28/10/201316/6/2026
Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.
ModificadaAlta (7.5)2.1%—Drusus LogsurferKerry Thompson Logsurfer+27/1/201216/6/2026
Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote attackers to execute arbitrary commands via crafted strings in a log file.
ModificadaMedia (5)8.6%💥 ExploitMotorola Surfboard Sbv6120e16/6/201016/6/2026
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.
ModificadaAlta (7.5)22%💥 ExploitIF Surfalert Project IF Surfalert4/5/201016/6/2026
Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaMedia (4.3)0.87%—Surfstats5/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
ModificadaMedia (4.3)1.1%—Ljscripts Auto-surf Traffic Exchange Script30/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary web script or HTML via the rid parameter to (1) index.php, (2) faq.php, and (3) register.php.
ModificadaAlta (7.8)1.5%—Motorola Surfboard28/4/200816/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html, and (2) cause a denial of service (hard…
ModificadaAlta (7.8)1.4%—Gosurf Browser9/2/200716/6/2026
Cross-domain vulnerability in GoSuRF Browser 2.62 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that…
ModificadaAlta (7.8)7.8%💥 ExploitMotorola Surfboard10/10/200616/6/2026
The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.
ModificadaMedia (5)1.4%—Finjan Software Surfingate14/6/200516/6/2026
Finjan SurfinGate 7.0SP2 and SP3 allows remote attackers to download blocked files via hex-encoded characters in a filename, as demonstrated using "%2e".
ModificadaAlta (7.5)7.7%💥 ExploitFinjan Software Surfingate31/12/200416/6/2026
Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy…
ModificadaMedia (4.3)1.2%—Xperience Sandsurfer31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in unspecified Perl scripts in SandSurfer before 1.7.1 allow remote attackers to inject arbitrary web script or HTML, which is later executed by a target who views reports containing the injected data.
ModificadaMedia (4.6)0.40%—Info Touch Surfnet31/12/200416/6/2026
Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts.
ModificadaMedia (5)3.4%💥 ExploitLoom Software Surfnow ProfessionalLoom Software Surfnow Standard31/12/200416/6/2026
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.
ModificadaMedia (4.6)0.69%💥 ExploitInfo Touch Surfnet31/12/200416/6/2026
Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command.
ModificadaBaja (2.1)0.32%—Info Touch Surfnet KioskAI31/12/200416/6/2026
Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.
ModificadaAlta (7.5)2.5%—Snapfiles Whisper FTP Surfer27/7/200416/6/2026
Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.
ModificadaAlta (7.5)1.8%—Sandsurfer8/2/200416/6/2026
Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.
ModificadaMedia (4.3)3.2%—ISC BindNixu NamesurferCompaq Tru64Freebsd+615/12/200316/6/2026
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
ModificadaMedia (5)2.6%—Surfcontrol Superscout Email Filter31/3/200316/6/2026
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter.
ModificadaMedia (5)5.9%💥 ExploitSurfcontrol Superscout Email Filter31/3/200316/6/2026
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form.
ModificadaMedia (4.3)3.6%💥 ExploitSurfcontrol Superscout Email Filter31/3/200316/6/2026
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter.
ModificadaMedia (5)2.6%—Surfcontrol Superscout Email Filter31/3/200316/6/2026
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it.
Orbitaley — Vulnerabilidades