Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2717▼ 139 respecto a la semana anterior
Críticas / altas1239▼ 297 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 202 respecto a la semana anterior
–

1017 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.5%—Toshiba Bluetooth Stack14/1/200616/6/2026
Vulnerabilidad de salto de directorio en servicios OBEX Push en Toshiba Bluetooth Stack 4.00.23(T) y versiones anteriores permite a atacantes remotos subir archivos arbitrarios a localizaciones remotas arbitrarias especificadas por secuencias .. (punto punto), según lo demostrado por secuencias ..\\ en el argumento…
ModificadaMedia (5)1.4%—Ariba Spend Management Solutions8/9/200516/6/2026
Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information.
ModificadaBaja (2.1)0.35%—Toshiba Acpi Flash Bios2/5/200516/6/2026
An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed. NOTE: it has been debated as to whether or not this issue poses a security vulnerability,…
ModificadaBaja (2.1)0.36%—Thibault Godouet FcronGentoo Linux1/3/200516/6/2026
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.
ModificadaBaja (2.1)0.36%—Thibault Godouet FcronGentoo Linux1/3/200516/6/2026
Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.
ModificadaAlta (7.2)0.37%—Thibault Godouet FcronGentoo Linux1/3/200516/6/2026
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as…
ModificadaBaja (2.1)0.36%—Thibault Godouet FcronGentoo Linux1/3/200516/6/2026
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be parsed in an error message.
ModificadaAlta (7.5)1.7%💥 ExploitFrancisco Burzi Php-nukeShiba-design Nukecalendar31/12/200416/6/2026
SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.
ModificadaMedia (5)3.5%💥 ExploitFrancisco Burzi Php-nukeShiba-design Nukecalendar31/12/200416/6/2026
The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.
ModificadaMedia (4.3)1.7%💥 ExploitFrancisco Burzi Php-nukeShiba-design Nukecalendar31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.
ModificadaBaja (2.6)0.77%💥 ExploitThibault Godouet Fcron20/9/200116/6/2026
Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.
ModificadaMedia (4.6)12%💥 ExploitHP Omniback IIHp-ux2/6/200116/6/2026
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.
ModificadaMedia (5)6.2%💥 ExploitComputer Software Manufaktur Alibaba18/7/200016/6/2026
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.
ModificadaMedia (5)9.7%💥 ExploitHP Openview Omniback II28/2/200016/6/2026
HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.
ModificadaMedia (5)1.1%—Computer Software Manufaktur Alibaba31/12/199916/6/2026
genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.
ModificadaBaja (3.6)2.8%💥 ExploitComputer Software Manufaktur Alibaba3/11/199916/6/2026
El servidor web Alibaba permite a un atacante remoto ejecutar comandos mediante un caráctar de tubería (barra vertical) en una URL malformada.
ModificadaMedia (5)1.4%—Computer Software Manufaktur Alibaba12/5/199916/6/2026
Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.