Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.1% | — | CA Xosoft Content DistributionCA Xosoft High AvailabilityXosoft Replication | 7/4/2010 | 16/6/2026 | CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP request. | |
| Modificada | Media (5) | 2.1% | — | CA Xosoft Content DistributionCA Xosoft High AvailabilityXosoft Replication | 7/4/2010 | 16/6/2026 | CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request. | |
| Modificada | Alta (7.5) | 1.8% | — | Airspan Base Station Distribution Unit | 28/3/2008 | 16/6/2026 | Airspan Base Station Distribution Unit (BSDU) has "topsecret" as its password for the root account, which allows remote attackers to obtain administrative access via a telnet login, a different vulnerability than CVE-2008-1262. | |
| Modificada | Alta (9.4) | 8.4% | 💥 Exploit | Rajneel LAL Totaram USP Foss Distribution | 25/4/2007 | 16/6/2026 | Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the dnld parameter. | |
| Modificada | Alta (9.3) | 9.7% | 💥 Exploit | Xampp Apache Distribution | 18/4/2007 | 16/6/2026 | The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, which allows remote attackers to trigger a library buffer overflow and execute arbitrary code via a long host parameter, or have other unspecified impact. NOTE: it could be… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Xampp Apache Distribution | 18/4/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts. | |
| Modificada | Media (5) | 1.6% | — | Xampp Apache Distribution | 17/6/2005 | 16/6/2026 | Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Xampp Apache Distribution | 12/4/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php. | |
| Modificada | Alta (7.5) | 4.7% | 💥 Exploit | Xampp Apache Distribution | 12/4/2005 | 16/6/2026 | XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges. | |
| Modificada | Media (5) | 1.6% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded. | |
| Modificada | Media (5) | 3.2% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets. | |
| Modificada | Alta (7.5) | 4.4% | — | Cisco Application AND Content Networking SoftwareCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content Distribution Manager 4670+5 | 5/1/2004 | 16/6/2026 | Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary code via a long password. | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content EngineCisco Enterprise Content Delivery Network Software+4 | 12/8/2002 | 16/6/2026 | The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP. |