Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.9%—Get-simple Getsimple CMS1/7/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post-content or (2) post-title parameter to admin/edit.php.
ModificadaMedia (5)2.5%—Cagintranetworks Getsimple CMSGet-simple Getsimple CMS20/1/201517/6/2026
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.
ModificadaMedia (4.3)3.2%💥 ExploitGet-simple Getsimple CMS14/5/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) param parameter to admin/load.php or (2) user, (3) email, or (4) name parameter in a Save Settings action to admin/settings.php.
ModificadaMedia (4.3)1.9%—Get-simple Getsimple CMS17/1/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1.2 and 3.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) post-menu field to edit.php or (2) Display name field to settings.php. NOTE: The Custom Permalink Structure and Email Address fields are already covered by…
ModificadaMedia (4.3)1.4%—Get-simple Getsimple CMS16/1/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1, 3.1.2, 3.2.3, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Email Address or (2) Custom Permalink Structure fields in admin/settings.php; (3) path parameter to admin/upload.php; (4) err parameter to…
ModificadaAlta (10)77%💥 ExploitEnterasys Netsight25/10/201216/6/2026
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via a long PRIO field in a message to UDP port 514.
ModificadaMedia (4.3)3.0%💥 ExploitGet-simple Getsimple CMS23/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the val[] parameter.
ModificadaMedia (4.3)3.3%💥 ExploitGet-simple Getsimple CMS5/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter.
ModificadaAlta (7.5)4.0%—Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager27/4/200716/6/2026
Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.
ModificadaAlta (7.8)1.9%—Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager27/4/200716/6/2026
The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field.
ModificadaAlta (9.3)2.4%—Netsieben SSH Library24/3/200716/6/2026
Buffer overflow in the Ne7sshSftp::addOpenHandle function in ne7ssh_sftp.cpp in NetSieben SSH Library (ne7ssh) before 1.2.1 allows user-assisted remote SFTP servers to cause a denial of service (crash) or possibly execute arbitrary code via multiple file transfers, related to multiple open file handles in SFTP (1) put…
ModificadaMedia (5)1.5%—Hitachi JPI Netsight II Port Discovery AdvanceHitachi JPI Netsight II Port Discovery Standard21/1/200616/6/2026
Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".
ModificadaMedia (4.6)1.5%—Microsoft PsexecMicrosoft PsgetsidMicrosoft PsinfoMicrosoft Pskill+731/12/200416/6/2026
Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not…
ModificadaMedia (6.8)4.4%💥 ExploitBBC Education Betsie4/10/200216/6/2026
Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to execute arbitrary web script via parserl.pl.
Orbitaley — Vulnerabilidades