Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | Cisco Staros | 29/4/2015 | 17/6/2026 | The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and call-processing outage) via malformed PM packets, aka Bug ID CSCut94711. | |
| Modificada | Alta (10) | 5.3% | — | Justsystems IchitaroJustsystems Ichitaro PRO | 26/11/2014 | 17/6/2026 | Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro Pro 2; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen; and Ichitaro 2014 Tetsu allows remote attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (5.4) | 0.27% | — | Instaroid - Instagram Viewer Project Instaroid - Instagram Viewer | 30/9/2014 | 17/6/2026 | The Instaroid - Instagram Viewer (aka net.muik.instaroid) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.6) | 3.6% | — | Justsystems IchitaroJustsystems Just Online Update | 16/6/2014 | 17/6/2026 | JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature. | |
| Modificada | Alta (9.3) | 4.6% | — | Justsystems Ichitaro PROJustsystems Ichitaro Portable With OreplugJustsystems IchitaroJustsystems Ichitaro Viewer | 13/11/2013 | 16/6/2026 | Unspecified vulnerability in JustSystems Ichitaro 2006 through 2011; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen and Gen Trial Edition; Ichitaro Pro; Ichitaro Pro 2 and Pro 2 Trial Edition; Ichitaro Viewer; and Ichitaro Portable with oreplug allows remote… | |
| Modificada | Media (5.8) | 2.5% | — | Cisco IOSCisco IOS XECisco ASA 5500Cisco PIX Firewall Software+3 | 5/8/2013 | 16/6/2026 | The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote… | |
| Modificada | Alta (10) | 4.2% | — | Justsystems IchitaroJustsystems Ichitaro Just SchoolJustsystems Ichitaro PortableJustsystems Ichitaro Viewer | 18/6/2013 | 16/6/2026 | Unspecified vulnerability in JustSystems Ichitaro 2006 through 2013; Ichitaro Pro through 2; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro Portable with oreplug; Ichitaro Viewer; and Ichitaro JUST School through 2010 allows remote attackers to execute arbitrary code via a crafted document. | |
| Modificada | Alta (9.3) | 3.8% | — | Justsystems HanakoJustsystems Hanako PoliceJustsystems Hanako Police3Justsystems Ichitaro+1 | 1/3/2013 | 16/6/2026 | Unspecified vulnerability in JustSystems Ichitaro 2006 and 2007, Ichitaro Government 2006 and 2007, Ichitaro Portable with oreplug, Hanako 2006 through 2013, Hanako Police, Hanako Police 3, and Hanako Police 2010 allows remote attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (4.3) | 3.5% | — | Astaro Security Gateway SoftwareAstaro Security GatewaySophos Unified Threat Management SoftwareSophos Unified Threat Management | 9/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field. | |
| Modificada | Media (6.9) | 0.40% | — | Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+3 | 27/4/2012 | 16/6/2026 | Untrusted search path vulnerability in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, and oreplug allows local users to gain privileges via a Trojan… | |
| Modificada | Alta (9.3) | 4.2% | — | Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+7 | 27/4/2012 | 16/6/2026 | Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro4, Shuriken 2007 through 2010, Shuriken Pro4 Corporate Edition,… | |
| Modificada | Alta (9.3) | 5.6% | — | Justsystems IchitaroJustsystems Ichitaro PortableJustsystems Ichitaro PROJustsystems Ichitaro Viewer | 18/7/2011 | 16/6/2026 | JustSystems Ichitaro 2005 through 2011, Ichitaro Government 6, Ichitaro Government 2006 through 2010, Ichitaro Portable, Ichitaro Pro, and Ichitaro Viewer allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document, as exploited in the wild in early… | |
| Modificada | Alta (9.3) | 5.6% | — | Justsystems Ichitaro | 6/11/2010 | 16/6/2026 | Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3915. | |
| Modificada | Alta (9.3) | 6.1% | — | Justsystems Ichitaro | 6/11/2010 | 16/6/2026 | Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3916. | |
| Modificada | Alta (9.3) | 5.6% | — | Justsystems IchitaroJustsystems Just School | 3/6/2010 | 16/6/2026 | Unspecified vulnerability in JustSystems Ichitaro 2004 through 2009, Ichitaro Government 2006 through 2009, and Just School 2008 and 2009 allows remote attackers to execute arbitrary code via unknown vectors related to "product character attribute processing" for a document. | |
| Modificada | Alta (9.3) | 4.0% | — | Justsystems Ichitaro | 15/4/2010 | 16/6/2026 | Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government 2006 through 2010 allows user-assisted remote attackers to execute arbitrary code via a crafted font file. | |
| Modificada | Alta (9.3) | 3.5% | — | Justsystems IchitaroJustsystems Ichitaro Viewer | 6/4/2010 | 16/6/2026 | Stack-based buffer overflow in JustSystems Corporation Ichitaro 13, 2004 through 2009, Viewer 2009 19.0.1.0 and earlier, and other versions allows context-dependent attackers to execute arbitrary code via a crafted Rich Text File (RTF), related to "pvpara ffooter." | |
| Modificada | Baja (3.5) | 1.9% | 💥 Exploit | Autartica COM Autartitarot | 2/3/2010 | 16/6/2026 | Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authenticated users, with "Public Back-end" group permissions, to read arbitrary files via directory traversal sequences in the controller parameter in an edit task to administrator/index.php. NOTE: some… | |
| Modificada | Alta (9.3) | 3.9% | — | IchitaroIchitaro Viewer | 24/3/2009 | 16/6/2026 | Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to execute arbitrary code via a crafted file, as exploited in the wild by Trojan.Tarodrop.H in March 2009. | |
| Modificada | Alta (10) | 2.4% | — | Atarone | 8/10/2008 | 16/6/2026 | Directory traversal vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme_chosen parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.0% | — | Atarone | 8/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ap-pages.php in Atarone CMS 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) id parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 0.99% | — | Atarone | 8/10/2008 | 16/6/2026 | SQL injection vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) site_name, (2) email, (3) theme_chosen, (4) hp, (5) c_meta, (6) id, and (7) c_js parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Alta (9.3) | 3.9% | — | Justsystems Ichitaro | 4/9/2008 | 16/6/2026 | Unspecified vulnerability in multiple JustSystems Ichitaro products allows remote attackers to execute arbitrary code via a crafted JTD document, as exploited in the wild in August 2008. | |
| Modificada | Alta (9.3) | 4.8% | — | Justsystem IchitaroJustsystem Ichitaro Lite2Justsystem Ichitaro Viewer | 10/1/2008 | 16/6/2026 | Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file. | |
| Modificada | Alta (9.3) | 4.1% | — | Justsystem Ichitaro | 18/12/2007 | 16/6/2026 | Stack-based buffer overflow in JSGCI.DLL in JustSystems Ichitaro 2005, 2006, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted document, as actively exploited in December 2007 by the Tarodrop.F trojan. NOTE: some of these details are obtained from third party information. |