Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.9% | — | Get-simple Getsimple CMS | 1/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post-content or (2) post-title parameter to admin/edit.php. | |
| Modificada | Media (5) | 2.5% | — | Cagintranetworks Getsimple CMSGet-simple Getsimple CMS | 20/1/2015 | 17/6/2026 | XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Get-simple Getsimple CMS | 14/5/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) param parameter to admin/load.php or (2) user, (3) email, or (4) name parameter in a Save Settings action to admin/settings.php. | |
| Modificada | Media (4.3) | 1.9% | — | Get-simple Getsimple CMS | 17/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1.2 and 3.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) post-menu field to edit.php or (2) Display name field to settings.php. NOTE: The Custom Permalink Structure and Email Address fields are already covered by… | |
| Modificada | Media (4.3) | 1.4% | — | Get-simple Getsimple CMS | 16/1/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1, 3.1.2, 3.2.3, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Email Address or (2) Custom Permalink Structure fields in admin/settings.php; (3) path parameter to admin/upload.php; (4) err parameter to… | |
| Modificada | Alta (10) | 77% | 💥 Exploit | Enterasys Netsight | 25/10/2012 | 16/6/2026 | Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via a long PRIO field in a message to UDP port 514. | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | Get-simple Getsimple CMS | 23/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the val[] parameter. | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Get-simple Getsimple CMS | 5/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter. | |
| Modificada | Alta (7.5) | 4.0% | — | Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager | 27/4/2007 | 16/6/2026 | Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names. | |
| Modificada | Alta (7.8) | 1.9% | — | Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager | 27/4/2007 | 16/6/2026 | The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field. | |
| Modificada | Alta (9.3) | 2.4% | — | Netsieben SSH Library | 24/3/2007 | 16/6/2026 | Buffer overflow in the Ne7sshSftp::addOpenHandle function in ne7ssh_sftp.cpp in NetSieben SSH Library (ne7ssh) before 1.2.1 allows user-assisted remote SFTP servers to cause a denial of service (crash) or possibly execute arbitrary code via multiple file transfers, related to multiple open file handles in SFTP (1) put… | |
| Modificada | Media (5) | 1.5% | — | Hitachi JPI Netsight II Port Discovery AdvanceHitachi JPI Netsight II Port Discovery Standard | 21/1/2006 | 16/6/2026 | Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data". | |
| Modificada | Media (4.6) | 1.5% | — | Microsoft PsexecMicrosoft PsgetsidMicrosoft PsinfoMicrosoft Pskill+7 | 31/12/2004 | 16/6/2026 | Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not… | |
| Modificada | Media (6.8) | 4.4% | 💥 Exploit | BBC Education Betsie | 4/10/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to execute arbitrary web script via parserl.pl. |