Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.90% | — | Fossura TAG Miner | 17/9/2019 | 17/6/2026 | The fossura-tag-miner plugin before 1.1.5 for WordPress has XSS. | |
| Modificada | Alta (8.8) | 0.68% | — | Fossura TAG Miner | 17/9/2019 | 17/6/2026 | The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 1.3% | — | Cisco Socialminer | 24/1/2019 | 17/6/2026 | A vulnerability in the chat feed feature of Cisco SocialMiner could allow an unauthenticated, remote attacker to perform cross-site scripting (XSS) attacks against a user of the web-based user interface of an affected system. This vulnerability is due to insufficient sanitization of user-supplied input delivered to… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Socialminer | 17/10/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration Mediation FulfillmentCisco Mediasense+9 | 7/6/2018 | 17/6/2026 | Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain… | |
| Modificada | Alta (8.8) | 3.9% | — | Cgminer Project CgminerBfgminer | 5/6/2018 | 17/6/2026 | The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers. | |
| Modificada | Media (6.5) | 2.4% | — | BfgminerCgminer Project Cgminer | 5/6/2018 | 17/6/2026 | The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal). | |
| Modificada | Alta (8.8) | 16% | 💥 Exploit | Bitmain Antminer D3 FirmwareBitmain Antminer L3+ FirmwareBitmain Antminer S9 Firmware | 31/5/2018 | 17/6/2026 | Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function. | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Socialminer | 17/5/2018 | 17/6/2026 | A vulnerability in the TCP stack of Cisco SocialMiner could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the notification system. The vulnerability is due to faulty handling of new TCP connections to the affected application. An attacker could exploit this vulnerability by… | |
| Modificada | Crítica (9.8) | 4.4% | — | Adminer | 5/3/2018 | 17/6/2026 | Adminer through 4.3.1 has SSRF via the server parameter. | |
| Modificada | Alta (7.5) | 77% | 💥 Exploit | Nanopool Claymore Dual Miner | 9/2/2018 | 17/6/2026 | Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write mode enabled. | |
| Modificada | Crítica (9.1) | 44% | 💥 Exploit | Claymore Dual Miner Project Claymore Dual Miner | 2/2/2018 | 17/6/2026 | The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service. | |
| Modificada | Crítica (9.8) | 34% | 💥 Exploit | Claymore Dual Miner Project Claymore Dual Miner | 5/12/2017 | 17/6/2026 | The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. This can be exploited via a long API request that is mishandled during logging. | |
| Modificada | Alta (8.1) | 13% | 💥 Exploit | Claymore Dual Miner Project Claymore Dual Miner | 5/12/2017 | 17/6/2026 | The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a remote attacker to read/write arbitrary files. This can be exploited via ../ sequences in the pathname to miner_file or… | |
| Modificada | Crítica (9.8) | 6.4% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration SolutionCisco Mediasense+7 | 16/11/2017 | 17/6/2026 | A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration… | |
| Modificada | Media (5.3) | 1.1% | — | Ewbf Cuda Zcash Miner | 15/10/2017 | 17/6/2026 | The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Service attack preventing a user from viewing their mining statistics by an attacker opening a session with telnet or… | |
| Modificada | Alta (8.8) | 2.9% | — | Cisco Socialminer | 7/9/2017 | 17/6/2026 | A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to information stored in the affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could… | |
| Modificada | Media (6.1) | 1.3% | — | Cisco Socialminer | 4/7/2017 | 17/6/2026 | A vulnerability in the web framework of Cisco SocialMiner could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCve15285. Known Affected Releases: 11.5(1). | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Socialminer | 4/11/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212. | |
| Modificada | Media (6) | 1.0% | — | Cpuminer Project Cpuminer | 25/10/2014 | 17/6/2026 | Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a mining.subscribe response with a large nonce2 length, then triggering the overflow with a mining.notify request. | |
| Modificada | Media (4.3) | 1.2% | — | Sgminer Project SgminerCgminer Project Cgminer | 23/7/2014 | 17/6/2026 | The parse_notify function in util.c in sgminer before 4.2.2 and cgminer 3.3.0 through 4.0.1 allows man-in-the-middle attackers to cause a denial of service (application exit) via a crafted (1) bbversion, (2) prev_hash, (3) nbit, or (4) ntime parameter in a mining.notify action stratum message. | |
| Modificada | Alta (10) | 3.3% | — | BfgminerSgminer Project Sgminer | 23/7/2014 | 17/6/2026 | Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a mining.subscribe response and a crafted… | |
| Modificada | Alta (10) | 2.9% | — | Sgminer Project SgminerCgminer Project CgminerBfgminer | 23/7/2014 | 17/6/2026 | Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions in util.c. | |
| Modificada | Media (5) | 1.2% | — | Cisco Socialminer | 13/9/2013 | 16/6/2026 | administration.jsp in Cisco SocialMiner allows remote attackers to obtain sensitive information by sniffing the network for HTTP client-server traffic, aka Bug ID CSCuh76780. | |
| Modificada | Media (5) | 1.4% | — | Cisco Socialminer | 13/9/2013 | 16/6/2026 | The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID CSCuh74125. |