Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1086 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.9%—Cisco Content Services Switch 115005/4/200616/6/2026
Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) "valid, but obsolete" or (2) "specially crafted" HTTP requests.
ModificadaAlta (7.5)1.2%—Ideosoft Design Ideocontent Manager27/1/200616/6/2026
Multiple SQL injection vulnerabilities in index.php in IdeoContent Manager allow remote attackers to execute arbitrary SQL commands via the (1) goto_id or (2) mid parameter.
ModificadaMedia (4.3)1.2%—Ideosoft Design Ideocontent Manager27/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows remote attackers to inject arbitrary web script or HTML via the (1) goto_id parameter to index.php or (2) page parameter to news_full.php.
ModificadaMedia (4.3)1.2%—Goldstag Content Management System27/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in Goldstag Content Management System allows remote attackers to inject arbitrary web script or HTML via the text parameter.
ModificadaAlta (10)19%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+3031/12/200516/6/2026
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
ModificadaMedia (5)2.4%—Cisco Application AND Content Networking SoftwareCisco ATACisco Subscriber Edge Services ManagerCisco IP Phone 7902+331/12/200516/6/2026
Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect offset.
ModificadaAlta (7.5)1.2%—Antharia Oncontent CMS31/12/200516/6/2026
SQL injection vulnerability in index.php in Antharia OnContent // CMS allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it is not clear, but this might be an application service provider, in which case it might be excluded from CVE.
ModificadaMedia (4.3)1.7%💥 ExploitPaperthin Commonspot Content Server29/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.
ModificadaMedia (5)1.4%—Paperthin Commonspot Content Server29/12/200516/6/2026
PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting error message.
ModificadaMedia (4.3)1.2%—Nqcontent20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in NQcontent 3 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the text parameter.
ModificadaAlta (7.5)1.1%💥 ExploitContentserv20/12/200516/6/2026
Vulnerabilidad de inyección de SQL en index.php en ContentServ 3.1 y anteriores permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro "StoryID".
ModificadaAlta (7.5)1.1%—Icms Content Management Systems Icms20/12/200516/6/2026
SQL injection vulnerability in RunScript.asp iCMS allows remote attackers to execute arbitrary SQL commands via the Event_ID parameter.
ModificadaMedia (4.3)0.94%—Icms Content Management Systems Icms20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.
ModificadaMedia (4.3)1.7%💥 ExploitMagnolia Content Management Suite20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
ModificadaMedia (5.8)1.7%💥 ExploitHOT Banana WEB Content Management Suite20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.cfm in Hot Banana Web Content Management Suite 5.3 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
ModificadaBaja (2.1)0.33%—IBM DB2 Content Manager16/11/200516/6/2026
db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."
ModificadaMedia (5)1.5%—Icms Content Management Systems Icms16/11/200516/6/2026
PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter.
ModificadaMedia (5)1.4%—IBM DB2 Content Manager16/11/200516/6/2026
INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files.
ModificadaMedia (4.6)0.40%—Sony First4internet XCP Content Management3/11/200516/6/2026
The aries.sys driver in Sony First4Internet XCP DRM software hides any file, registry key, or process with a name that starts with "$sys$", which allows attackers to hide activities on a system that uses XCP.
ModificadaMedia (5)1.0%—Cisco Content Services Switch 115002/11/200516/6/2026
Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation.
ModificadaMedia (6.4)1.9%—Contentserv27/9/200516/6/2026
Directory traversal vulnerability in admin/about.php in contentServ 3.1 allows remote attackers to read or include arbitrary files via ".." sequences in the ctsWebsite parameter.
ModificadaMedia (4.3)1.0%—Content2web21/9/200516/6/2026
PHP file inclusion vulnerability in index.php in Content2Web 1.0.1 allows remote attackers to include arbitrary files via the show parameter, which can lead to resultant errors such as path disclosure, SQL error messages, and cross-site scripting (XSS).
ModificadaAlta (7.5)1.9%—WEB Content Management News System7/8/200516/6/2026
Web Content Management News System permite a atacantes remotos crear cuentas de su elección y ganar privilegios mediante una petición directa a Admin/Users/AddModifyInput.php.
ModificadaMedia (4.3)1.8%💥 ExploitWEB Content Management News System7/8/200516/6/2026
Vulnerabilidad de scritps en sitios cruzados (XSS) en Web Content Management News System permite a atacantes remotos inyectar script web arbitrario o HTML mediante el parámetro strRootpath de validsession.php o el parámetro strTable de Admin/News/List.php
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.