Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.9%💥 ExploitDigitizing Quote AND Ordering System9/1/200716/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en search.asp de Digitizing Quote And Ordering System 1.0 permite a atacantes autenticados remotamente inyectar secuencias de comandos web o HTML de su elección a través del parámetro ordernum.
ModificadaMedia (6)0.94%💥 ExploitDigitizing Quote AND Ordering System31/12/200616/6/2026
Vulnerabilidad de inyección SQL en search.asp en Digitizing Quote And Ordering System 1.0 permite a usuarios autenticados remotamente ejecutar comandos SQL de su elección a través del parámetro ordernum.
ModificadaMedia (5)1.5%—Novell Bordermanager13/10/200616/6/2026
Vulnerabilidad no especificada en IKE.NLM en Novell BorderManager 3.8 permite a un atacante remoto provocar denegación de servicio (caida) a través de un ataque desconocido de vectores realciones con "asunto VPN" para ciertas "configuraciones IKE y IPsec".
ModificadaAlta (10)2.7%—Borderware Mxtreme19/3/200616/6/2026
Unspecified vulnerability in BorderWare MXtreme 5.0 and 6.0 allows remote attackers to have an unknown impact via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)1.6%—Novell Bordermanager14/3/200616/6/2026
Unspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consumption and ABEND) via unknown attack vectors related to "media streaming over HTTP 1.1".
ModificadaAlta (10)19%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+3031/12/200516/6/2026
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
ModificadaMedia (5)2.1%—Novell Bordermanager31/12/200416/6/2026
The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via a malformed IKE packet, as sent by the Striker ISAKMP Protocol Test Suite.
ModificadaMedia (5)1.8%—Novell Bordermanager12/8/200216/6/2026
RTSP proxy for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a GET request to port 9090 followed by a series of carriage returns, which causes proxy.nlm to ABEND.
ModificadaMedia (5)1.7%—Novell Bordermanager12/8/200216/6/2026
IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to ABEND.
ModificadaMedia (5)1.7%—Novell Bordermanager12/8/200216/6/2026
FTP proxy server for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service (network connectivity loss) via a connection to port 21 with a large amount of random data.
ModificadaMedia (5)1.7%—Novell Bordermanager12/8/200216/6/2026
Novell BorderManager 3.5 with PAT (Port-Address Translate) enabled allows remote attackers to cause a denial of service by filling the connection table with a large number of connection requests to hosts that do not have a specific route, which may be forwarded to the public interface.
ModificadaMedia (5)5.0%💥 ExploitNovell Bordermanager2/7/200116/6/2026
Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.
ModificadaMedia (5)1.8%—Borderware Firewall Server2/6/200116/6/2026
Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the network.
ModificadaAlta (7.5)1.8%—Novell Bordermanager7/7/200016/6/2026
The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.
ModificadaMedia (5)1.4%—Novell Bordermanager5/7/200016/6/2026
Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.
ModificadaMedia (5)5.5%💥 ExploitNovell Bordermanager30/3/200016/6/2026
Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000.
ModificadaAlta (7.5)2.1%—Make-a-store Orderpage1/2/200016/6/2026
The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
ModificadaMedia (5)1.1%—Austin Contract Computing Merchant Order Form1/4/199916/6/2026
An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information.
ModificadaAlta (7.5)2.7%—Network Flight Recorder16/2/199916/6/2026
Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.
Orbitaley — Vulnerabilidades