Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1086 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)6.1%—Cisco IOSCisco Css11000 Content Services SwitchCisco PIX FirewallOpenssl+11/12/200316/6/2026
OpenSSL 0.9.6k, cuando se ejecuta en Windows, permite a atacantes remotos causar una denegación de servicio (caída por recursión excesiva) mediante secuencias ASN.1 malformadas.
ModificadaAlta (7.5)2.9%—Vignette Content SuiteVignette StoryserverVignette2/7/200316/6/2026
Vignette StoryServer 4 y 5, y Vignette V/5 y V/6, con la característica SSI EXEC habilitada, permite a atacantes remotos ejecutar código arbitrario mediante una varible de texto a una Aplicacíón Vignette que es mostrada posteriormente.
ModificadaMedia (6.4)1.6%—Vignette Content SuiteVignette StoryserverVignette2/7/200316/6/2026
Vignette StoryServer 4 y 5, Vignette V/5, y posiblemente otras versiones permite a atacantes remtos llevar a cabo consultas SELECT no autorizadas estableciendo la cookie vgn_creds a un valor arbitrario y accediendo directamente a la plantilla de guardado.
ModificadaMedia (4.3)2.0%💥 ExploitVignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Multiples de vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Vignette StoryServer 4 y 5, y Vignette V/5 y V/6, permite a atacantes remotos insertar HTML arbitrario y script mediante variables de texto, como se ha demostrado usanod el parámetro errinfo de la plantilla de inicio de sesión por…
ModificadaMedia (5)3.5%💥 ExploitVignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Vignette StoryServer y Vignette V/5 no calcula adecuadamente el tamaño de variables de texto, lo que hace que devuelva trozos de contenido de memoria no autorizado, como se ha demostrado usando la cadena "-->" en un argumento CookieName de la plantilla de inicio de sesión, referido como "fuga de memora" en algunos…
ModificadaAlta (7.5)2.5%—Vignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Vignette StoryServer 5 y Vignette V/5 permite a atacantes remotos leer y modificar información de licencia, u causar una denegación de servicio (parada del servicio) accediendo directamente a la plantilla /vgn/license.
ModificadaMedia (5)2.3%—Vignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Vignette StoryServer y Vignette V/5 permite a atacantes remotos obtener información sensible mediante una petición a la plantilla /vgn/style
ModificadaMedia (5)1.5%—Vignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
La plantilla de inicio de sesíón por defecto (/vgn/login) en Vignette StoryServer 5 y Vignette V/5 genera diferentes respuestas si un usuario existe o no, lo que permite a atacantes remotos identificar nombres de usuario válidos mediante ataques de fuerza bruta.
ModificadaMedia (5)1.6%—Vignette Content SuiteVignette StoryserverVignette30/6/200316/6/2026
Vignette StoryServer 5 y Vignette V/6 permite a atacantes remotos ejecutar código TCL arbitrario mediante una consulta o cookie HTTP que es procesada en el comando NEEDS, o un remitidor HTTP que es procesado en el comando VALID_PATHS
ModificadaMedia (6.8)23%💥 ExploitMicrosoft Content Management Server7/2/200316/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en ManualLogin.asp de Microsoft Content Management (MCMS) 2001 permite a atacantes remotos ejecutar script arbitriario mediante el parámetro REASONTXT.
ModificadaMedia (5)1.3%—Sonicwall Content Filtering31/12/200216/6/2026
SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name.
ModificadaAlta (7.5)1.9%—Visualshapers Ezcontents4/10/200216/6/2026
Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.
ModificadaAlta (7.1)3.3%—Cisco IOSCisco PIX Firewall SoftwareCisco Css11000 Content Services SwitchCisco Catos4/10/200216/6/2026
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).
ModificadaMedia (5)1.5%—Visualshapers Ezcontents4/10/200216/6/2026
The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.
ModificadaMedia (5)1.8%—Visualshapers Ezcontents4/10/200216/6/2026
Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences.
ModificadaMedia (5)2.3%—Adobe Content Server4/10/200216/6/2026
The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook even when the maximum number of loans is exceeded by accessing the "Add to bookbag" feature when the server reports that no more copies are available.
ModificadaMedia (6.4)2.6%—Visualshapers Ezcontents4/10/200216/6/2026
The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.
ModificadaAlta (7.5)2.5%—Visualshapers Ezcontents4/10/200216/6/2026
Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.
ModificadaMedia (5)2.5%—Adobe Content Server4/10/200216/6/2026
The library feature for Adobe Content Server 3.0 does not verify if a customer has already checked out an eBook, which allows remote attackers to cause a denial of service (resource exhaustion) by checking out the same book multiple times.
ModificadaMedia (5)2.6%—Adobe Content Server4/10/200216/6/2026
The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook for an arbitrary length of time via a modified loanMin parameter to download.asp.
ModificadaMedia (5)1.7%—Visualshapers Ezcontents4/10/200216/6/2026
The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upload files via a direct HTTP POST request.
ModificadaAlta (7.5)1.5%—Cisco WebnsCisco Content Services Switch 110005/9/200216/6/2026
El parche original para la vulnerabilidad de evasión de autenticación (CVE-2001-0622) de Cisco Content Service Switch 11000 Series estaba incompleto, lo que aún permite a atacantes remotos ganar privilegios adicionales pidiendo directamente la URL de administración web en vez de navegando a través del interfaz,…
ModificadaAlta (7.5)7.9%—Microsoft Content Management Server12/8/200216/6/2026
Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise."
ModificadaAlta (7.5)1.6%—Cisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content EngineCisco Enterprise Content Delivery Network Software+412/8/200216/6/2026
The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP.
ModificadaAlta (7.5)10%—Microsoft Content Management Server12/8/200216/6/2026
SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.