Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

924 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.6%—Mediatrix Telecom Voip Access Devices AND Gateways31/12/200316/6/2026
The Session Initiation Protocol (SIP) implementation in Mediatrix Telecom VoIP Access Devices and Gateways running SIPv2.4 and SIPv4.3 firmware allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
ModificadaMedia (4.3)3.9%💥 ExploitCitrix Metaframe31/12/200316/6/2026
Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.
ModificadaMedia (4.3)0.66%—Citrix Access EssentialsCitrix Metaframe Presentation ServerCitrix Presentation Server31/12/200216/6/2026
Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an…
ModificadaAlta (7.2)0.46%—Digital OSF 1Digital Ultrix4/10/200216/6/2026
Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.
ModificadaAlta (7.5)1.6%—Deepmetrix Livestats4/10/200216/6/2026
Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program.
ModificadaAlta (7.5)7.9%💥 ExploitCitrix Nfuse12/8/200216/6/2026
Vulnerabilidad de secuencias de comandos de sitios cruzados (cross-site scripting) en Citrix NFuse 1.6 y anteriores no pone entre comillas a los resultados del método getLastError, lo que permite a atacantes remotos ejecutar comandos en otros clientes mediante el parámetro NFuse_Application para lanzar launch.jsp o…
ModificadaMedia (5)2.5%—Citrix Nfuse12/8/200216/6/2026
Vulnerabilidad de atravesamiento de directorios en boilerplate.asp para Citrix NFuse 1.5 permite a usuarios identificados remotamente leer ficheros mediante un .. (punto punto) en el parámetro NFuse_Template.
ModificadaMedia (5)3.6%💥 ExploitCitrix Nfuse12/8/200216/6/2026
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.
ModificadaMedia (5)2.0%—Citrix Nfuse31/5/200216/6/2026
Citrix NFuse 1.6 permite a atacantes remotos sortear la autenticación y obtener información sensible llamando directamente a launch.asp con parámetros NFUSE_USER y NFUSE_PASSWORD inválidos.
ModificadaAlta (7.5)1.9%—Matrixs CGI Vault Last Lines30/12/200116/6/2026
Matrix CGI vault Last Lines 2.0 permite a atacantes remotos ejecutar código arbitrario por fallo en la validación de metacarácteres de shell
ModificadaMedia (5)2.6%—Matrixs CGI Vault Last Lines30/12/200116/6/2026
Vulnerabilidad de atravesamiento de directorios en lastlines.cgi para Last Lines 2.0 permite a atacantes remotos la lectura arbitraria de ficheros mediante un ataque '..' (punto punto).
ModificadaAlta (7.5)2.2%—Citrix ICA Client13/12/200116/6/2026
El cliente Citrix Independent Computing Architecture (ICA) para Windows 6.1 permite a sitios web remotos con intenciones maliciosas, la ejecución de código arbitrario mediante un fichero .ICA, que es descargado y automáticamente ejecutado por el cliente.
ModificadaMedia (5)1.7%—Citrix Metaframe6/12/200116/6/2026
Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server.
ModificadaAlta (7.5)1.4%—Citrix Metaframe21/11/200116/6/2026
CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).
ModificadaMedia (5)3.6%💥 ExploitCitrix Nfuse18/10/200116/6/2026
Citrix Nfuse 1.51 permite a atacantes remotos obtener la ruta absoluta de la raíz del web mediante una petición malformada que no provee el campo de sesión.
ModificadaAlta (10)2.3%💥 ExploitCitrix MetaframeCitrix Winframe29/3/200016/6/2026
The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.
ModificadaMedia (4.6)0.41%—Macromedia Matrix Screen Saver4/10/199916/6/2026
Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.
ModificadaMedia (5)1.9%—Tetrix Tetrinet17/2/199916/6/2026
Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.
ModificadaMedia (5)1.8%—Digital UltrixLinux KernelNetbsdOpenbsd+124/8/199716/6/2026
rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.
ModificadaAlta (10)52%💥 ExploitBsdi BSD OSDebian LinuxDigital UltrixFreebsd+66/2/199716/6/2026
Buffer overflow of rlogin program using TERM environmental variable.
ModificadaAlta (7.5)19%—Digital Ultrix1/1/199716/6/2026
Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.
ModificadaAlta (10)2.4%—Digital Ultrix31/12/199116/6/2026
Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.
ModificadaMedia (4.6)0.32%—Digital Ultrix23/8/199116/6/2026
Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.
ModificadaAlta (7.2)0.96%💥 ExploitDigital Ultrix1/5/199116/6/2026
chroot en Digital Ultrix 4.1 y 4.0 es instalado de forma insegura, lo que permite a usuarios locales para ganar privilegios.
Orbitaley — Vulnerabilidades