Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.49% | — | Northadamsbank Nasb Mobile Bank | 16/6/2017 | 17/6/2026 | The North Adams State Bank (Ursa) nasb-mobile-banking/id980573797 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.5) | 0.29% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread denials of service to system services by consuming TCP and UDP ports which are normally reserved for other system services. | |
| Modificada | Alta (7.5) | 0.97% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to perform a man-in-the-middle attack, thereby stealing authentic credentials from encrypted paths which are easily decrypted, and subsequently gain… | |
| Modificada | Media (6.5) | 1.1% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A persistent denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network-based, authenticated attacker to consume enough system resources to cause a persistent denial of service by visiting certain specific URLs on the server. | |
| Modificada | Alta (8.8) | 2.3% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network based, unauthenticated attacker to perform privileged actions to gain complete control over the environment. | |
| Modificada | Alta (7.3) | 1.1% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A firewall bypass vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to bypass firewall policies, leading to authentication bypass methods, information disclosure, modification of system files, and denials of service. | |
| Modificada | Media (6.2) | 0.32% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbit virus, or wabbit, which will create processes that replicate themselves, until all resources are… | |
| Modificada | Media (6.2) | 0.36% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivileged system files capable of causing widespread denials of system services. | |
| Modificada | Media (5.5) | 0.32% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to elevate their permissions through reading unprivileged information stored in the NorthStar controller. | |
| Modificada | Media (5.5) | 0.30% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to consume large amounts of system resources leading to a cascading denial of services. | |
| Modificada | Media (6.5) | 1.1% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, network-based attacker to replicate the underlying Junos OS VM and all data it maintains to their local system for future analysis. | |
| Modificada | Media (6.5) | 1.2% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service. | |
| Modificada | Media (5.3) | 2.0% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to cause a denial of service condition. | |
| Modificada | Alta (7.5) | 1.3% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker crafting packets destined to the device to cause a persistent denial of service to the path computation server service. | |
| Modificada | Alta (8.6) | 1.5% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of… | |
| Modificada | Crítica (10) | 1.9% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including… | |
| Modificada | Alta (8.3) | 1.1% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, leading to managed systems being compromised or services being denied to authentic end users and… | |
| Modificada | Media (6.5) | 0.99% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or provide elevation of privileges. | |
| Modificada | Alta (8.6) | 0.95% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system… | |
| Modificada | Media (6.5) | 0.32% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service. | |
| Modificada | Media (5.4) | 0.27% | — | Graphicstylus North American Ismaili Games | 16/10/2014 | 17/6/2026 | The North American Ismaili Games (aka hr.apps.n166983741) application 5.26.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Enorth Webpublisher CMS | 9/12/2013 | 17/6/2026 | SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows remote attackers to execute arbitrary SQL commands via the thisday parameter. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | North Country Public Radio Public Media Manager | 1/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc.php in North Country Public Radio Public Media Manager (PMM) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the indir parameter. | |
| Modificada | Media (5) | 1.5% | — | Northern Solutions Xeneo WEB Server | 9/5/2006 | 16/6/2026 | Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension. | |
| Modificada | Alta (7.8) | 3.8% | 💥 Exploit | OCE North America 3121 PrinterOCE North America 3122 Printer | 29/4/2006 | 16/6/2026 | parser.exe in Océ (OCE) 3121/3122 Printer allows remote attackers to cause a denial of service (crash or reboot) via a long request, possibly triggering a buffer overflow. |