Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

150 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Zemana Antilogger18/8/201817/6/2026
A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2.ini under %LOCALAPPDATA%\Zemana\ZALSDK) to permit execution of unauthorized applications (such as ones that record…
ModificadaAlta (7.5)2.8%—Weechat Logger23/9/201717/6/2026
logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.
ModificadaAlta (7.5)3.2%—Schneider-electric Wonderware Archestra Logger7/7/201717/6/2026
A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The null pointer dereference vulnerability could allow an attacker to crash the logger process, causing a denial of service for logging and log-viewing (applications that use the…
ModificadaCrítica (9.8)9.8%—Schneider-electric Wonderware Archestra Logger7/7/201717/6/2026
A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow a remote attacker to execute arbitrary code in the context of a highly privileged account.
ModificadaAlta (8.6)4.1%💥 PoCSchneider-electric Wonderware Archestra Logger7/7/201717/6/2026
An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The uncontrolled resource consumption vulnerability could allow an attacker to exhaust the memory resources of the machine, causing a denial of service.
ModificadaAlta (8.8)16%—Satel-iberia Sennet Multitask MeterSatel-iberia Sennet Optimal DataloggerSatel-iberia Sennet Solar Datalogger19/5/201717/6/2026
A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this vulnerability could result in the…
ModificadaMedia (6.3)0.85%—HP Arcsight Logger16/1/201617/6/2026
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
ModificadaAlta (7.3)2.3%—HP Arcsight Logger16/1/201617/6/2026
HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
ModificadaMedia (4.3)1.9%—HP Archsight Management CenterHP Arcsight Logger12/11/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.2)0.61%—HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+34/11/201517/6/2026
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
ModificadaMedia (5)4.4%—HP Arcsight Logger4/11/201517/6/2026
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.
ModificadaMedia (4)1.8%—HP Arcsight Logger16/9/201517/6/2026
HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.
ModificadaAlta (9)12%💥 ExploitHP Arcsight Logger14/3/201517/6/2026
Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors.
ModificadaMedia (5)1.4%—Plogger29/12/201417/6/2026
Plogger 1.0 RC1 and earlier, when the Lucid theme is used, does not assign new values for certain codes, which makes it easier for remote attackers to bypass the CAPTCHA protection mechanism via a series of form submissions.
ModificadaMedia (5.4)0.27%—Masquito2013 Masquito Blogger21/10/201417/6/2026
The Masquito Blogger (aka com.wmasquito) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)10%💥 ExploitPlogger11/9/201417/6/2026
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then accessing the PHP file via a direct request to it in…
ModificadaMedia (6.8)0.94%—HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger16/2/201316/6/2026
Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to execute arbitrary code via unknown vectors.
ModificadaMedia (5)3.8%—HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger16/2/201316/6/2026
Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and earlier allows remote attackers to obtain sensitive information via unknown vectors.
ModificadaMedia (6.5)2.4%—HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger16/2/201316/6/2026
Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.
ModificadaAlta (7.5)1.3%—Plogger4/10/201216/6/2026
Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) index.php or (2) gallery.php.
ModificadaMedia (4.3)2.6%—HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger Appliance FirmwareHP Arcsight Logger Appliance8/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.
ModificadaAlta (7.5)0.91%💥 ExploitMblogger Project Mblogger7/10/201116/6/2026
SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands via the postID parameter.
ModificadaMedia (6.8)2.0%💥 ExploitDaman371 Bloggeruniverse12/9/201116/6/2026
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified vectors.
ModificadaBaja (3.5)1.8%—Michael Hudson-doyle Loggerhead29/3/201116/6/2026
Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.
ModificadaAlta (7.5)5.8%💥 ExploitGraviton-mediatech Visitor Logger3/6/201016/6/2026
PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_include_path parameter.
Orbitaley — Vulnerabilidades