Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Subscribers.jsp" has reflected XSS via the ConnPoolName or GroupId parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/SubFolderPackages.jsp" has reflected XSS via the GroupId parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Import.jsp" has reflected XSS via the ConnPoolName parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/GroupMove.jsp" has reflected XSS via the ConnPoolName, GroupId, or type parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/GroupCopy.jsp" has reflected XSS via the ConnPoolName, GroupId, or type parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "Variables.jsp" has reflected XSS via the ConnPoolName and GroupId parameters. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "PresentSpace.jsp" has reflected XSS via the GroupId and ConnPoolName parameters. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentUser.jsp" has reflected XSS via the GroupId and ConnPoolName parameters. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPresentSpace.jsp" has reflected XSS via the ConnPoolName, GroupId, and ParentId parameters. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPool.jsp" has reflected XSS via the PropName parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "Users.jsp" has reflected XSS via the ConnPoolName parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "UserProperties.jsp" has reflected XSS via the ConnPoolName parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "SubPagePackages.jsp" has reflected XSS via the ConnPoolName and GroupId parameters. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "PresentSpace.jsp" has reflected XSS via the ConnPoolName and GroupId parameters. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "GroupRessourceAdmin.jsp" has reflected XSS via the ConnPoolName parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPresentSpace.jsp" has reflected XSS via the ConnPoolName, GroupId, and ParentId parameters. | |
| Modificada | Media (6.1) | 1.1% | — | Infovista Vistaportal | 17/12/2018 | 17/6/2026 | XSS exists in InfoVista VistaPortal SE Version 5.1 (build 51029). VPortal/mgtconsole/RolePermissions.jsp has reflected XSS via the ConnPoolName parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Chatbyvista Project Chatbyvista | 7/6/2018 | 17/6/2026 | chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Media (5.5) | 2.9% | 💥 PoC | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Vista+1 | 26/2/2018 | 17/6/2026 | An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged attacker to leak 16 bits of uninitialized kernel PagedPool… | |
| Modificada | Alta (7) | 1.5% | 💥 PoC | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Vista+1 | 26/2/2018 | 17/6/2026 | An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. Two carefully timed calls to IOCTL 0xCA002813 can cause a race condition that leads to a use-after-free. When exploited, an unprivileged attacker… | |
| Modificada | Alta (7.8) | 1.8% | — | Jpki THE Public Certification Service FOR IndividualsJpki THE Public Certification Service FOR Individuals FOR Windows 7Jpki THE Public Certification Service FOR Individuals FOR Windows Vista | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)" Ver3.0.1 and earlier and The Public Certification Service… | |
| Analizada | Alta (7.8) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft OfficeMicrosoft Windows 7Microsoft Windows Server 2008Microsoft Windows Server 2012+2 | 12/4/2017 | 17/6/2026 | Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution… | |
| Modificada | Media (4.3) | 6.0% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+4 | 12/4/2017 | 17/6/2026 | The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gain sensitive information via a specially crafted document or… | |
| Modificada | Alta (8.1) | 6.4% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+4 | 12/4/2017 | 17/6/2026 | An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege… | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+4 | 12/4/2017 | 17/6/2026 | An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability." |