Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.8% | — | Samsung Data Management Server | 9/5/2011 | 16/6/2026 | SQL injection vulnerability in the authentication form in the integrated web server in the Data Management Server (DMS) before 1.4.3 in Samsung Integrated Management System allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Media (4.3) | 0.91% | — | Novell Suse Lifecycle Management Server | 3/9/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the apache2-slms package in SUSE Lifecycle Management Server (SLMS) 1.0 on SUSE Linux Enterprise (SLE) 11 allows remote attackers to hijack the authentication of unspecified victims via vectors related to improper parameter quoting. NOTE: some sources report that this… | |
| Analizada | Alta (10) | 94% | 💥 Exploit | IBM Websphere Application ServerApache Http ServerIBM Http ServerOracle Http Server+1 | 5/3/2010 | 16/6/2026 | modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute… | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Imperva SecuresphereImperva Securesphere MX Management Server | 24/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbitrary web script or HTML via an invalid or prohibited request to a web server protected by SecureSphere, which triggers injection into the "corrective action" section of… | |
| Modificada | Alta (7.5) | 15% | — | Openpegasus Management ServerVmware ESX | 8/1/2008 | 16/6/2026 | Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003. | |
| Modificada | Alta (10) | 7.8% | — | Openpegasus Management Server | 8/1/2008 | 16/6/2026 | Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUS_USE_PAM_STANDALONE_PROC defined, might allow remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than… | |
| Modificada | Alta (10) | 46% | — | Microsoft Content Management Server | 10/4/2007 | 16/6/2026 | Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability." | |
| Modificada | Media (4.3) | 16% | — | Microsoft Content Management Server | 10/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability." | |
| Modificada | Alta (10) | 7.2% | — | Eudora Worldmail Management Server | 31/12/2006 | 16/6/2026 | Heap-based buffer overflow in the Mail Management Server (MAILMA.exe) in Eudora WorldMail 3.1.x allows remote attackers to execute arbitrary code via a crafted request containing successive delimiters. | |
| Modificada | Alta (7.5) | 22% | — | Novell Zenworks Patch Management Server | 10/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in dagent/downloadreport.asp in Novell ZENworks Patch Management (ZPM) before 6.3.2.700 allow remote attackers to execute arbitrary SQL commands via the (1) agentid and (2) pass parameters. | |
| Modificada | Media (6.8) | 1.2% | — | Link Content Management Server | 8/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in naprednaPretraga.php in LINK Content Management Server (CMS) allows remote attackers to inject arbitrary web script or HTML via the txtPretraga parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Link Content Management Server | 8/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php. NOTE: The provenance of this information is unknown; the details… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Symantec Sygate Management Server | 2/2/2006 | 16/6/2026 | SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL. | |
| Modificada | Alta (7.5) | 5.4% | 💥 Exploit | Novell Zenworks Patch Management Server | 30/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp. | |
| Modificada | Media (5) | 25% | 💥 Exploit | Microsoft Systems Management Server | 27/7/2004 | 16/6/2026 | The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address. | |
| Modificada | Media (6.8) | 23% | 💥 Exploit | Microsoft Content Management Server | 7/2/2003 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter. | |
| Modificada | Alta (7.5) | 7.9% | — | Microsoft Content Management Server | 12/8/2002 | 16/6/2026 | Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise." | |
| Modificada | Alta (7.5) | 6.0% | — | Microsoft Content Management Server | 12/8/2002 | 16/6/2026 | Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function." | |
| Modificada | Alta (7.5) | 10% | — | Microsoft Content Management Server | 12/8/2002 | 16/6/2026 | SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files. | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Systems Management ServerMicrosoft Windows 2000Microsoft Windows NT | 19/12/2000 | 23/9/2026 | Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this… | |
| Modificada | Alta (7.2) | 2.8% | 💥 Exploit | Microsoft Systems Management Server | 29/12/1999 | 16/6/2026 | The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program. |