Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

1063 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.0%—Hosting Controller12/8/200216/6/2026
Hosting Controller 1.4.1 and earlier allows remote attackers to browse arbitrary directories via a full C: style pathname in the filepath arguments to (1) Statsbrowse.asp, (2) servubrowse.asp, (3) browsedisk.asp, (4) browsewebalizerexe.asp, or (5) sqlbrowse.asp.
ModificadaAlta (10)4.5%💥 ExploitHosting Controller12/8/200216/6/2026
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters such as (1) ftp, (2) owwwPath, and (3) oftpPath.
ModificadaAlta (7.5)1.6%—Symantec Norton Ghost25/6/200216/6/2026
Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.
ModificadaAlta (7.5)2.1%—Aladdin Enterprises Ghostscript29/5/200216/6/2026
ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice.
ModificadaAlta (7.5)1.6%—Hosting Controller16/5/200216/6/2026
El registro de usuarios en Hosting Controller versiones 1.1 a la 1.4.1 devuleve diferentes mensajes de error cuando intentan conectarse usuarios válidos y no válidos, lo que permite a atacantes remotos determinar la existencia de nombres válidos de usuario lo que hace más fácil llevar a cabo un ataque por fuerza bruta.
ModificadaBaja (2.6)0.32%—Aladdin Enterprises Ghostscript18/9/200116/6/2026
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
ModificadaMedia (5)1.8%—Symantec Norton Ghost2/8/200116/6/2026
Symantec Ghost 6.5 and earlier allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to the Ghost Configuration Server on port 1347, which triggers an error that is not properly handled.
ModificadaAlta (7.5)20%—Microsoft Internet ExplorerMicrosoft Windows Script Host21/7/200116/6/2026
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
ModificadaMedia (5)5.1%💥 ExploitIBM Net.commerceIBM Net.commerce Hosting ServerIBM Websphere Application Server2/7/200116/6/2026
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
ModificadaAlta (7.5)7.1%💥 ExploitIBM Net.commerceIBM Net.commerce Hosting ServerIBM Websphere Commerce Suite3/5/200116/6/2026
orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.
ModificadaBaja (3.7)0.32%—Aladdin Enterprises Ghostscript9/1/200116/6/2026
ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.
ModificadaMedia (4.6)0.40%—Aladdin Enterprises Ghostscript9/1/200116/6/2026
ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.
ModificadaAlta (7.5)2.8%—Aladdin Enterprises Ghostscript31/8/199516/6/2026
The ghostscript command with the -dSAFER option allows remote attackers to execute commands.