Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

1212 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.4%💥 ExploitAuthoria31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command parameter.
ModificadaAlta (7.5)2.9%—Stellar-x Software Msntauth4/10/200216/6/2026
Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.
ModificadaAlta (7.5)2.9%—C-note Squid Auth LdapPadl Software NSS LdapPadl Software PAM Ldap12/8/200216/6/2026
Vulnerabilidad de cadena de formato en la función logging() en el módulo de autenticación de C-Note Squid LDAP 2.0.2 y anteriores permite que un atacante remoto provoque una denegación de servicio y, posiblemente, ejecute código arbitrario desencadenando mensajes de log.
ModificadaAlta (7.5)4.1%—Valicert Enterprise Validation Authority4/12/200116/6/2026
Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6)…
ModificadaAlta (7.5)2.3%—Valicert Enterprise Validation Authority4/12/200116/6/2026
Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed.
ModificadaAlta (7.5)1.6%—Valicert Enterprise Validation Authority4/12/200116/6/2026
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which…
ModificadaAlta (7.5)2.5%—Valicert Enterprise Validation Authority4/12/200116/6/2026
Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.
ModificadaAlta (7.5)1.9%—Guiseppe Tanzilli AND Matthias Eckermann MOD Auth Pgsql29/8/200116/6/2026
The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name.
ModificadaMedia (5)1.8%—Flicks Software Authentix9/1/200116/6/2026
Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.
ModificadaMedia (5)7.7%💥 ExploitNetwin Netauth20/10/200016/6/2026
netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
ModificadaAlta (7.5)1.8%—Hughes Technologies W3-auth30/9/199916/6/2026
Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header.
ModificadaAlta (7.5)3.2%💥 ExploitRAY Chan WWW Authorization Gateway8/7/199816/6/2026
Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter.