Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 4.9% | ⚠ Explotación activa | Trustedconnectivityalliance S@T Browser | 12/9/2019 | 17/6/2026 | Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker. | |
| Modificada | Crítica (9.8) | 2.0% | — | Srtalliance Secure Reliable Transport | 29/8/2019 | 17/6/2026 | Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections. | |
| Modificada | Alta (7.5) | 1.1% | — | Swift Alliance WEB Platform | 5/7/2019 | 17/6/2026 | An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjBlnvocationException error log information containing null@java:comp/env/ error messages. | |
| Modificada | Media (5.4) | 0.60% | — | Intersect Alliance Snare Epilog | 17/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in InterSect Alliance SNARE Epilog for UNIX version 1.5 allows remote authenticated users to inject arbitrary web script or HTML via the str_log_name parameter in a "Web Admin Portal > Log Configuration > Add" action. | |
| Modificada | Media (4.3) | 1.4% | — | Intersectalliance System Intrusion Analysis AND Reporting Environment | 14/5/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the events page in the System iNtrusion Analysis and Reporting Environment (SNARE) for Linux agent before 1.7.0 allows remote attackers to inject arbitrary web script or HTML via a logged shell command. | |
| Modificada | Media (6.8) | 1.5% | — | Intersect Alliance Snare AgentIntersect Alliance Snare Epilog | 2/7/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in InterSect Alliance Snare Agent 3.2.3 and earlier on Solaris, Snare Agent 3.1.7 and earlier on Windows, Snare Agent 1.5.0 and earlier on Linux and AIX, Snare Agent 1.4 and earlier on IRIX, Snare Epilog 1.5.3 and earlier on… | |
| Modificada | Alta (7.2) | 0.32% | — | Openhandsetalliance Android SDK | 17/2/2009 | 16/6/2026 | Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions. | |
| Modificada | Alta (7.2) | 0.30% | — | Openhandsetalliance Android SDK | 17/2/2009 | 16/6/2026 | The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbitrary files owned by certain groups, possibly a related issue to… | |
| Modificada | Alta (10) | 1.5% | — | Osads Alliance Database | 24/9/2008 | 16/6/2026 | Unspecified vulnerability in OSADS Alliance Database before 2.1 has unknown impact and attack vectors, possibly related to includes/functions.php, a different issue than CVE-2006-2874. | |
| Modificada | Media (4.3) | 1.1% | — | Osads Alliance Database | 6/6/2006 | 16/6/2026 | Unspecified vulnerability in OSADS Alliance Database before 1.4 has unknown impact and attack vectors related to a "Security Leak to lock in HTML-Code," possibly due to a cross-site scripting (XSS) vulnerability involving comments. |