Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Zemana Antilogger | 18/8/2018 | 17/6/2026 | A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2.ini under %LOCALAPPDATA%\Zemana\ZALSDK) to permit execution of unauthorized applications (such as ones that record… | |
| Modificada | Alta (7.5) | 2.8% | — | Weechat Logger | 23/9/2017 | 17/6/2026 | logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized. | |
| Modificada | Alta (7.5) | 3.2% | — | Schneider-electric Wonderware Archestra Logger | 7/7/2017 | 17/6/2026 | A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The null pointer dereference vulnerability could allow an attacker to crash the logger process, causing a denial of service for logging and log-viewing (applications that use the… | |
| Modificada | Crítica (9.8) | 9.8% | — | Schneider-electric Wonderware Archestra Logger | 7/7/2017 | 17/6/2026 | A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow a remote attacker to execute arbitrary code in the context of a highly privileged account. | |
| Modificada | Alta (8.6) | 4.1% | 💥 PoC | Schneider-electric Wonderware Archestra Logger | 7/7/2017 | 17/6/2026 | An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The uncontrolled resource consumption vulnerability could allow an attacker to exhaust the memory resources of the machine, causing a denial of service. | |
| Modificada | Alta (8.8) | 16% | — | Satel-iberia Sennet Multitask MeterSatel-iberia Sennet Optimal DataloggerSatel-iberia Sennet Solar Datalogger | 19/5/2017 | 17/6/2026 | A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this vulnerability could result in the… | |
| Modificada | Media (6.3) | 0.85% | — | HP Arcsight Logger | 16/1/2016 | 17/6/2026 | HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. | |
| Modificada | Alta (7.3) | 2.3% | — | HP Arcsight Logger | 16/1/2016 | 17/6/2026 | HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. | |
| Modificada | Media (4.3) | 1.9% | — | HP Archsight Management CenterHP Arcsight Logger | 12/11/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.61% | — | HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+3 | 4/11/2015 | 17/6/2026 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. | |
| Modificada | Media (5) | 4.4% | — | HP Arcsight Logger | 4/11/2015 | 17/6/2026 | HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach. | |
| Modificada | Media (4) | 1.8% | — | HP Arcsight Logger | 16/9/2015 | 17/6/2026 | HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors. | |
| Modificada | Alta (9) | 12% | 💥 Exploit | HP Arcsight Logger | 14/3/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors. | |
| Modificada | Media (5) | 1.4% | — | Plogger | 29/12/2014 | 17/6/2026 | Plogger 1.0 RC1 and earlier, when the Lucid theme is used, does not assign new values for certain codes, which makes it easier for remote attackers to bypass the CAPTCHA protection mechanism via a series of form submissions. | |
| Modificada | Media (5.4) | 0.27% | — | Masquito2013 Masquito Blogger | 21/10/2014 | 17/6/2026 | The Masquito Blogger (aka com.wmasquito) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Plogger | 11/9/2014 | 17/6/2026 | Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then accessing the PHP file via a direct request to it in… | |
| Modificada | Media (6.8) | 0.94% | — | HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger | 16/2/2013 | 16/6/2026 | Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Media (5) | 3.8% | — | HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger | 16/2/2013 | 16/6/2026 | Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and earlier allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Media (6.5) | 2.4% | — | HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger | 16/2/2013 | 16/6/2026 | Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Plogger | 4/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) index.php or (2) gallery.php. | |
| Modificada | Media (4.3) | 2.6% | — | HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger Appliance FirmwareHP Arcsight Logger Appliance | 8/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Mblogger Project Mblogger | 7/10/2011 | 16/6/2026 | SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands via the postID parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Daman371 Bloggeruniverse | 12/9/2011 | 16/6/2026 | SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified vectors. | |
| Modificada | Baja (3.5) | 1.8% | — | Michael Hudson-doyle Loggerhead | 29/3/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view. | |
| Modificada | Alta (7.5) | 5.8% | 💥 Exploit | Graviton-mediatech Visitor Logger | 3/6/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_include_path parameter. |