Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2717▼ 139 respecto a la semana anterior
Críticas / altas1239▼ 297 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 202 respecto a la semana anterior
1017 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.5% | — | Toshiba Bluetooth Stack | 14/1/2006 | 16/6/2026 | Vulnerabilidad de salto de directorio en servicios OBEX Push en Toshiba Bluetooth Stack 4.00.23(T) y versiones anteriores permite a atacantes remotos subir archivos arbitrarios a localizaciones remotas arbitrarias especificadas por secuencias .. (punto punto), según lo demostrado por secuencias ..\\ en el argumento… | |
| Modificada | Media (5) | 1.4% | — | Ariba Spend Management Solutions | 8/9/2005 | 16/6/2026 | Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information. | |
| Modificada | Baja (2.1) | 0.35% | — | Toshiba Acpi Flash Bios | 2/5/2005 | 16/6/2026 | An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed. NOTE: it has been debated as to whether or not this issue poses a security vulnerability,… | |
| Modificada | Baja (2.1) | 0.36% | — | Thibault Godouet FcronGentoo Linux | 1/3/2005 | 16/6/2026 | fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string. | |
| Modificada | Baja (2.1) | 0.36% | — | Thibault Godouet FcronGentoo Linux | 1/3/2005 | 16/6/2026 | Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable. | |
| Modificada | Alta (7.2) | 0.37% | — | Thibault Godouet FcronGentoo Linux | 1/3/2005 | 16/6/2026 | fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as… | |
| Modificada | Baja (2.1) | 0.36% | — | Thibault Godouet FcronGentoo Linux | 1/3/2005 | 16/6/2026 | fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be parsed in an error message. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter. | |
| Modificada | Baja (2.6) | 0.77% | 💥 Exploit | Thibault Godouet Fcron | 20/9/2001 | 16/6/2026 | Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file. | |
| Modificada | Media (4.6) | 12% | 💥 Exploit | HP Omniback IIHp-ux | 2/6/2001 | 16/6/2026 | Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Computer Software Manufaktur Alibaba | 18/7/2000 | 16/6/2026 | Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request. | |
| Modificada | Media (5) | 9.7% | 💥 Exploit | HP Openview Omniback II | 28/2/2000 | 16/6/2026 | HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555. | |
| Modificada | Media (5) | 1.1% | — | Computer Software Manufaktur Alibaba | 31/12/1999 | 16/6/2026 | genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext. | |
| Modificada | Baja (3.6) | 2.8% | 💥 Exploit | Computer Software Manufaktur Alibaba | 3/11/1999 | 16/6/2026 | El servidor web Alibaba permite a un atacante remoto ejecutar comandos mediante un caráctar de tubería (barra vertical) en una URL malformada. | |
| Modificada | Media (5) | 1.4% | — | Computer Software Manufaktur Alibaba | 12/5/1999 | 16/6/2026 | Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack. |