Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Authoria | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command parameter. | |
| Modificada | Alta (7.5) | 2.9% | — | Stellar-x Software Msntauth | 4/10/2002 | 16/6/2026 | Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call. | |
| Modificada | Alta (7.5) | 2.9% | — | C-note Squid Auth LdapPadl Software NSS LdapPadl Software PAM Ldap | 12/8/2002 | 16/6/2026 | Vulnerabilidad de cadena de formato en la función logging() en el módulo de autenticación de C-Note Squid LDAP 2.0.2 y anteriores permite que un atacante remoto provoque una denegación de servicio y, posiblemente, ejecute código arbitrario desencadenando mensajes de log. | |
| Modificada | Alta (7.5) | 4.1% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6)… | |
| Modificada | Alta (7.5) | 2.3% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed. | |
| Modificada | Alta (7.5) | 1.6% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which… | |
| Modificada | Alta (7.5) | 2.5% | — | Valicert Enterprise Validation Authority | 4/12/2001 | 16/6/2026 | Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path. | |
| Modificada | Alta (7.5) | 1.9% | — | Guiseppe Tanzilli AND Matthias Eckermann MOD Auth Pgsql | 29/8/2001 | 16/6/2026 | The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name. | |
| Modificada | Media (5) | 1.8% | — | Flicks Software Authentix | 9/1/2001 | 16/6/2026 | Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Netwin Netauth | 20/10/2000 | 16/6/2026 | netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Alta (7.5) | 1.8% | — | Hughes Technologies W3-auth | 30/9/1999 | 16/6/2026 | Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | RAY Chan WWW Authorization Gateway | 8/7/1998 | 16/6/2026 | Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter. |