Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

1071 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.8)5.5%💥 ExploitCisco Wireless LAN Solution Engine21/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.
ModificadaAlta (7.5)2.8%—Cisco User Registration ToolCisco Wireless LAN Solution EngineCiscoworks 2000 Service Management SolutionCisco Hosting Solution Engine+121/4/200616/6/2026
Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell…
ModificadaMedia (4.3)1.2%—Arabless Saphplesson11/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary web script or HTML via the Word parameter. NOTE: it is possible that this issue is resultant from SQL injection.
ModificadaMedia (5)1.1%💥 ExploitArabless Saphplesson28/3/200616/6/2026
SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.
ModificadaAlta (7.5)1.8%—Avaya Wireless Ap-3Avaya Wireless Ap-4Avaya Wireless Ap-5Avaya Wireless Ap-6+616/12/200516/6/2026
Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and AP-2000 before 2.5.5, and Proxim AP-700 and AP-4000 after 2.4.11 and before 3.1, use a static WEP key of "12345", which allows remote attackers to bypass authentication.
ModificadaMedia (5)1.6%—Dell Truemobile 2300 Wireless Broadband Router8/12/200516/6/2026
Dell TrueMobile 2300 Wireless Broadband Router running firmware 3.0.0.8 and 5.1.1.6, and possibly other versions, allows remote attackers to reset authentication credentials, then change configuration or firmware, via a direct request to apply.cgi with the Page parameter set to adv_password.asp.
ModificadaAlta (7.5)2.1%—Cisco Unified Wireless IP Phone 7920 Firmware24/11/200516/6/2026
Cisco IP Phone (VoIP) 7920 1.0(8) contiene ciertas cadenas de comunidad SNMP fijas que no pueden ser cambiadas, lo que permite a atacantes remotos obtener información sensible.
ModificadaMedia (6.4)2.5%—Cisco 7920 Wireless IP Phone24/11/200516/6/2026
Cisco IP Phone (VoIP) 7920 1.0(8) escucha en el puerto UDP 17185 para soportar el depurador VxWorks, lo que permite a atacantes remotos obtener información sensible y causar una denegación de servicio.
ModificadaAlta (7.5)1.9%—Senao Si-680h Wireless Voip Phone21/11/200516/6/2026
Senao SI-680H Wireless VoIP Phone Firmware 0.03.0839 leaves the VxWorks debugger UDP port 17185 available without authentication, which allows attackers to access the phone OS, obtain sensitive information, and cause a denial of service.
ModificadaAlta (7.5)3.5%💥 ExploitSaphplesson30/10/200516/6/2026
SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.
ModificadaAlta (10)7.3%—Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2423/8/200516/6/2026
Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets.
ModificadaAlta (10)75%💥 ExploitBroadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2423/8/200516/6/2026
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (7.5)1.5%—Belkin 54G Wireless Router26/7/200516/6/2026
Los rúter inalámbricos Belkin 54g no fijan adecuadamente el password de administración, lo que permite que atacantes remotos ganen acceso mediante las interfaces de administración de Telnet o de web.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaMedia (5)1.2%—Belkin 54G Wireless Router2/5/200516/6/2026
The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors.
ModificadaAlta (7.5)1.4%—Belkin 54G Wireless Router2/5/200516/6/2026
Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication.
ModificadaAlta (7.5)4.5%—LesstifSGI PropackX.org X11r6Xfree86 Project X11r6+72/3/200516/6/2026
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
ModificadaBaja (2.1)0.33%—Checkpoint Check Point Integrity ClientZonelabs ZonealarmZonelabs Zonealarm Wireless Security11/2/200516/6/2026
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause…
ModificadaAlta (10)8.7%—LesstifX.org X11r6Xfree86 Project X11r6Gentoo Linux+210/1/200516/6/2026
Múltiples vulnerabilidades en libXpm 6.8.1 y anteriores, usada en XFree86 y otros paquetes, incluyendo (1) múltiples desbordamientos de enteros, (2) accesos de memoria fuera de límites, (3) atravesamiento de directorios, (4) metacaractéres de shell, (5) bucles infinitos, y (6) filtraciones de memoria podrían permitir…
ModificadaAlta (10)2.5%—GFI MailessentialsGFI Mailsecurity3/1/200516/6/2026
A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or…
ModificadaAlta (7.5)1.4%💥 ExploitIP3 Networks IP3 NetaccessIP3 Networks IP3 Netaccess - HospitalityIP3 Networks IP3 Netaccess - Wireless Hotspots31/12/200416/6/2026
SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was later reported to also affect firmware 4.0.34.
ModificadaMedia (6.4)2.0%—GNU Less31/12/200416/6/2026
Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless…
ModificadaMedia (6.4)1.7%—Zonet Zsr1104we Wireless Router Runtime Code31/12/200416/6/2026
The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions.
ModificadaAlta (10)2.4%—Symantec Clientless VPN Gateway 440031/12/200416/6/2026
Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact.
ModificadaAlta (7.5)1.7%—Sweex Wireless Broadband Router Accesspoint 802.11g31/12/200416/6/2026
Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file.
Orbitaley — Vulnerabilidades