Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1353 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 2.8% | — | Chris Desautels Node Parameter Control | 27/3/2013 | 16/6/2026 | The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to read and edit configuration options via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | HP Network Node Manager I | 6/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.1) | 12% | — | ISC BindRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+4 | 25/1/2013 | 16/6/2026 | ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record. | |
| Modificada | Media (4.3) | 1.2% | — | Nodewords Project Nodewords | 3/1/2013 | 16/6/2026 | The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description… | |
| Modificada | Alta (10) | 10% | — | HP Network Node Manager I | 6/12/2012 | 16/6/2026 | Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.1x and 9.20 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Colorbox Node Dennis Blake | 30/11/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Baja (3.5) | 0.96% | — | Christian Johansson Restrict Node Page View | 30/11/2012 | 16/6/2026 | The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "view any node page" or "view any node {type} page" permission to access unpublished nodes via a direct request. | |
| Modificada | Media (5.8) | 1.2% | — | Earl Dunovant Monthly Archive BY Node Type | 31/10/2012 | 16/6/2026 | The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attackers to access restricted nodes via unspecified vectors. | |
| Modificada | Media (5) | 4.2% | — | HP Network Node Manager I | 4/10/2012 | 16/6/2026 | Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.20 allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | HP Network Node Manager I | 20/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML via the (1) node parameter to nnm/mibdiscover; (2) nodename parameter to nnm/protected/configurationpoll.jsp, (3) nnm/protected/ping.jsp, (4) nnm/protected/statuspoll.jsp,… | |
| Modificada | Alta (7.5) | 2.9% | — | Hitachi Jp1/cm2/network Node Manager | 19/9/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in Hitachi JP1/Cm2/Network Node Manager i before 09-50-03 allow remote attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Baja (2.1) | 1.1% | — | Ariel Barreiro Noderecommendation | 18/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Node Recommendation module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 9.6% | — | HP Inode Management Center PC | 30/8/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in HP iNode Management Center before iNode PC 5.1 E0304 allow remote attackers to execute arbitrary code via crafted input, as demonstrated by a stack-based buffer overflow in iNodeMngChecker.exe for a crafted 0x0A0BF007 packet. | |
| Modificada | Media (6.8) | 1.2% | — | Node Limit Number Project Node Limitnumber | 14/8/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Node Limit Number module before 6.x-1.2 for Drupal allows remote attackers to hijack the authentication of users with the administer node limitnumber permission for requests that delete limits. | |
| Modificada | Media (6.4) | 2.6% | — | Nodejs | 13/8/2012 | 16/6/2026 | The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string. | |
| Modificada | Media (4.3) | 2.3% | — | HP Network Node Manager I | 7/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.64% | — | Justin Ellison Node Gallery | 25/7/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Node Gallery module for Drupal 6.x-3.1 and earlier allows remote attackers to hijack the authentication of certain users for requests that create node galleries. | |
| Modificada | Media (4.3) | 2.3% | — | Opensuse Project OpensusePostgresqlDebian LinuxRedhat Desktop Workstation+7 | 18/7/2012 | 16/6/2026 | PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters. | |
| Modificada | Media (4.3) | 1.6% | — | HP Network Node Manager I | 5/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 8.x, 9.0x, and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | Alexis Wilke Protected Node | 27/6/2012 | 16/6/2026 | The Protected Node module 6.x-1.x before 6.x-1.6 for Drupal does not properly "protect node access when nodes are accessed outside of the standard node view," which allows remote attackers to bypass intended access restrictions. | |
| Modificada | Media (6.8) | 1.2% | — | Ronan Dowling Node Hierarchy | 27/6/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Node Hierarchy module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to hijack the authentication of administrators for requests that change a node hierarchy position via an (1) up or (2) down action. | |
| Modificada | Media (4.3) | 2.8% | — | Scott Reynen Node Embed | 27/6/2012 | 16/6/2026 | The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0 for Drupal does not properly check permissions, which allows remote attackers to bypass intended access restrictions and read node titles. | |
| Modificada | Media (6.8) | 3.7% | — | Oracle MysqlRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+3 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690. | |
| Modificada | Baja (3.5) | 0.89% | — | Drupal Petition Node Module | 28/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition. | |
| Modificada | Media (4.3) | 2.2% | — | HP Network Node Manager I | 16/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4155. |