Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 5.0% | ⚠ Explotación activa | Redhat Automatic BUG Reporting ToolOracle LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+3 | 7/12/2015 | 27/8/2026 | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump. | |
| Modificada | Baja (3.6) | 0.90% | — | Redhat Automatic BUG Reporting ToolRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 7/12/2015 | 17/6/2026 | The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created directory with a predictable name in /var/tmp. | |
| Modificada | Media (6.8) | 1.0% | — | WP Limit Posts Automatically Project WP Limit Posts Automatically | 31/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the lpa_post_letters parameter in the… | |
| Modificada | Media (6.9) | 0.31% | — | Redhat Automatic BUG Reporting Tool | 12/3/2013 | 16/6/2026 | abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes." | |
| Modificada | Baja (3.7) | 0.45% | — | Redhat Automatic BUG Reporting Tool | 12/3/2013 | 16/6/2026 | Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module. | |
| Modificada | Baja (1.9) | 0.44% | — | Redhat Automatic BUG Reporting Tool | 3/7/2012 | 16/6/2026 | The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information. | |
| Modificada | Media (4.3) | 1.4% | — | Hitachi JP1 Integrated Management Service SupportHitachi Jp1/automatic JOB Management System 2-viewHitachi JOB Management Partner 1/automatic JOB Management System 2-viewHitachi JOB Management Partner 1/integrated Management-view+10 | 21/4/2010 | 16/6/2026 | Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated Management - View, and JP1/Cm2/SNMP System Observer, allows remote attackers to cause a denial of service ("abnormal" termination) via vectors related to the display of an "invalid GIF file." | |
| Modificada | Media (5) | 7.0% | — | X10media X10 Automatic MP3 Script | 12/8/2009 | 16/6/2026 | download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php. | |
| Modificada | Alta (7.5) | 3.0% | — | X10media .x10 Automatic MP3 Script | 24/9/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php. | |
| Modificada | Media (5) | 1.6% | — | Hitachi Jp1-cm2-network Node ManagerHitachi Jp1-cm2-network Node Manager 250Hitachi JPI Automatic JOB Management System 2Hitachi JPI Performance Management+5 | 27/4/2006 | 16/6/2026 | Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data. |