Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
1003 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 2.0% | — | Cisco Guard Ddos Mitigation Appliance | 21/9/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Cisco Guard DDoS Mitigation Appliance anterior a 5.1(6), cuando anti-spoofing está habilitado, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección vía cierta secuencia de caracteres en una URL que no es manejada… | |
| Modificada | Media (5) | 2.4% | — | GNU Privacy Guard | 13/3/2006 | 16/6/2026 | gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than… | |
| Modificada | Media (5.1) | 2.0% | — | Cisco Anomaly Guard ModuleCisco GuardCisco Traffic Anomaly Detector Module | 18/2/2006 | 16/6/2026 | The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server host" command, allows remote attackers to bypass… | |
| Modificada | Media (4.6) | 0.33% | — | Winability Folder Guard | 18/2/2006 | 16/6/2026 | WinAbility Folder Guard 4.11 allows local users to gain unauthorized access to certain capabilities of the application by renaming or moving the password file (FGuard.FGP), which disables the password requirement. | |
| Modificada | Media (4.6) | 1.4% | 💥 Exploit | GNU Privacy Guard | 15/2/2006 | 16/6/2026 | gpgv en GnuPG en versiones anteriores a 1.4.2.1, cuando se utiliza verificación de firma desatendida, devuelve un código de salida 0 en algunos casos, incluso cuando el archivo de firma acompañante no lleva una firma, esto puede provocar que los programas que usen gpgv asuman que la verificación de la firma ha tenido… | |
| Modificada | Media (4.6) | 0.33% | — | Winability Folder Guard | 17/11/2005 | 16/6/2026 | Folder Guard permite a usuarios locales evitar protecciones ejecutando desde o instalando en el directorio de archivos temporales. | |
| Modificada | Media (4.6) | 0.42% | — | GFI Languard Network Security Scanner | 2/5/2005 | 16/6/2026 | lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials. | |
| Modificada | Media (4.6) | 0.34% | — | Inca Nprotect Gameguard | 17/1/2005 | 16/6/2026 | npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges. | |
| Modificada | Media (5) | 1.4% | — | Daniel Barron Dansguardian | 31/12/2004 | 16/6/2026 | DansGuardian before 2.7.7-2 allows remote attackers to bypass URL filters via a ".." in the request. | |
| Modificada | Alta (7.5) | 4.6% | — | Enderunix SpamguardAI | 31/12/2004 | 16/6/2026 | Multiple stack-based and heap-based buffer overflows in EnderUNIX spamGuard before 1.7-BETA allow remote attackers to execute arbitrary code via the (1) qmail_parseline and (2) sendmail_parseline functions in parser.c, (3) loadconfig and (4) removespaces functions in loadconfig.c, and possibly (5) unspecified… | |
| Modificada | Alta (7.5) | 1.9% | — | Daniel Barron Dansguardian | 31/12/2004 | 16/6/2026 | DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename. | |
| Modificada | Media (5) | 1.4% | — | Daniel Barron Dansguardian | 31/12/2004 | 16/6/2026 | Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache. | |
| Modificada | Baja (2.1) | 0.44% | — | Diamondcs Process Guard Free | 31/12/2004 | 16/6/2026 | DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe. | |
| Modificada | Alta (10) | 3.7% | — | HP ServiceguardAIHP Cluster Object ManagerAI | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain privileges via unknown attack vectors. | |
| Modificada | Alta (7.5) | 73% | 💥 Exploit | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+7 | 15/4/2004 | 16/6/2026 | Múltiples desbordamientos de búfer basado en la pila en las rutinas de análisis de ICQ en el componente ISS Protocol Analysis Module (PAM), utilizado en varios productos RealSecure, Proventia y BlackICE, permite a atacantes remotos ejecutar código arbitrario mediante un respuesta SRV_MULTI conteniendo un paquete de… | |
| Modificada | Alta (7.5) | 8.0% | — | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+7 | 15/3/2004 | 16/6/2026 | Desbordamiento de búfer basado en la pila en el Módulo de análisis de Protocolos (PAM) de ISS, usado en ciertas versiones de RealSecure Network 7.0 y Server Sensor 7.0, Proventia series A, G, y M, Desktop 7.0 y 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, y BlackICE Server Protection… | |
| Modificada | Alta (7.5) | 2.8% | — | GNU Privacy Guard | 5/1/2004 | 16/6/2026 | Vulnerabilidad de cadena de formato en el cliente de GnuPG (gpg) 1.2.2 y anteriores permite a atacantes remotos o a un servidor de claves malicioso causar una denegación de servicio (caída) y posiblemente ejecutar código arbitrario durante un obtención de clave. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Daniel Barron Dansguardian | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter. | |
| Modificada | Media (5) | 2.9% | — | GNU Privacy Guard | 15/12/2003 | 16/6/2026 | GnuPG (GPG) 1.0.2 y otras versiones anteriores a 1.2.3 crea claves firma+cifra ElGamal usando el mismo componente para cifrado y para firma, lo que permite a atacantes determinar la clave privada a partir de una firma. | |
| Modificada | Media (4.6) | 0.36% | — | Watchguard Serverlock | 27/8/2003 | 16/6/2026 | WatchGuard ServerLock para Windows 2000 anteriores a SL 2.0.3 permite a usuarios locales cargar ficheros arbitrarios mediante la función OpenProcess(), como ha sido demostrado usando (1) un ataque de inyección de DLL, (2) ZwSetSystemInformation, y (3) una función API enganchada a OpenProcess. | |
| Modificada | Baja (2.1) | 0.35% | — | Watchguard Serverlock | 27/8/2003 | 16/6/2026 | WatchGuard ServerLock para Windows 2000 anteriores a SL 2.0.4 permite a usuarios locales acceder a memoria del kernel mediante un ataque de enlaces simbólicos en DevicePhysicalMemory | |
| Modificada | Alta (10) | 6.6% | — | GNU Privacy Guard | 27/5/2003 | 16/6/2026 | El código de validación de claves en GnuPG 1.2.2 no determina adecuadamente la validez de claves con múltiples IDs de usuario y asigna la máxima validez (de la ID de usuario más válida), lo que impide que GnuPG advierta cuando algunas de las ID no tengan un "trusted path". | |
| Modificada | Alta (10) | 2.8% | — | RapidstreamWatchguard Firebox | 2/4/2003 | 16/6/2026 | El interfaz CLI de WatchGuard Firebox Vclass 3.2 y anteriores, y RSSA Appliance 3.0.2 no cierra adecuadamente la conexión SSH cuando se provee una opción -N durante autenticación, lo que permite a atacantes remotos acceder a CLI con privilegios de administrador | |
| Modificada | Alta (10) | 4.3% | — | RapidstreamWatchguard Firebox | 2/4/2003 | 16/6/2026 | Vulnerabilidad de cadena de formato en el interfaz CLI de Watchguard Firebox Vclass 3.2 y anteriores, RSSA Appliance 3.0.2 permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante especificadores de cadenas de formateo en el parámetro de contraseña. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Engardelinux Guardian Digital WebtoolUserminWebmin | 3/3/2003 | 16/6/2026 | miniserv.pl en Webmin anterior a 1.070 y Usermin antes de 1.000 no maneja adecuadamente metacaractéres como avance de línea y retorno de carro (CRLF) en cadenas codificadas en Base-64 durante la autenticación básica, lo que permite a atacantes remotos suplantar un ID de sesión y ganar privilegios de root. |