Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 4.2% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3… | |
| Modificada | Media (6.8) | 2.3% | — | Kankun Smartsocket | 9/6/2015 | 17/6/2026 | The Kankun Smart Socket device and mobile application uses a hardcoded AES 256 bit key, which makes it easier for remote attackers to (1) obtain sensitive information by sniffing the network and (2) obtain access to the device by encrypting messages. | |
| Modificada | Media (6.8) | 0.69% | — | Socketmail | 25/7/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in home/secretqtn.php in SocketMail Pro 2.2.9 allows remote attackers to hijack the authentication of arbitrary users for requests that change user security questions and answers via an upd action. | |
| Modificada | Media (4.3) | 1.2% | — | Socketmail | 25/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SocketMail Pro 2.2.9 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. | |
| Modificada | Media (4) | 1.8% | — | Io-socket-ssl | 14/1/2011 | 16/6/2026 | The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, which allows remote attackers to bypass intended certificate restrictions. | |
| Modificada | Media (4.3) | 1.00% | — | Io-socket-ssl | 31/8/2009 | 16/6/2026 | The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate. | |
| Modificada | Alta (9.3) | 5.7% | — | Chilkatsoft Chilkat Socket | 12/8/2009 | 16/6/2026 | Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll 2.3.1.1 allows remote attackers to overwrite arbitrary files via the SaveLastError method. NOTE: this might be related to CVE-2008-1647. | |
| Modificada | Alta (10) | 6.4% | — | Tibco Enterprise Message ServiceTibco RtworksTibco SmartsocketsTibco Smartsockets Rtserver | 30/4/2009 | 16/6/2026 | Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks Server (aka RTserver), SmartSockets client libraries and add-on products, RTworks libraries and… | |
| Modificada | Alta (10) | 6.4% | — | Tibco Enterprise Message ServiceTibco RtworksTibco Smartsockets Rtserver | 16/1/2008 | 16/6/2026 | Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing size and copy-length values that trigger the overflow. | |
| Modificada | Alta (10) | 5.5% | — | Tibco RtworksTibco Smartsockets RtserverTibco Enterprise Message Service | 16/1/2008 | 16/6/2026 | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets. | |
| Modificada | Alta (10) | 5.5% | — | Tibco RtworksTibco Smartsockets RtserverTibco Enterprise Message Service | 16/1/2008 | 16/6/2026 | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointers. | |
| Modificada | Alta (10) | 5.4% | — | Tibco Enterprise Message ServiceTibco RtworksTibco Smartsockets Rtserver | 16/1/2008 | 16/6/2026 | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted requests that control loop operations related to memory. | |
| Modificada | Media (4.3) | 1.3% | — | Trolltech Qsslsocket | 8/1/2008 | 16/6/2026 | QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user. | |
| Modificada | Media (5) | 2.2% | — | Alhem C++ Sockets Library | 8/11/2007 | 16/6/2026 | HTTPSocket.cpp in the C++ Sockets Library before 2.2.5 allows remote attackers to cause a denial of service (crash) via an HTTP request with a missing protocol version number, which triggers an exception. NOTE: some of these details were obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | — | Socketmail | 23/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Socketkb | 23/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SocketKB 1.1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) art_id or (2) node parameter in an article action to the default URI. | |
| Modificada | Media (6.8) | 2.1% | — | Socketmail | 23/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote attackers to execute arbitrary PHP code via a URL in the __SOCKETMAIL_ROOT parameter. | |
| Modificada | Alta (7.5) | 2.7% | — | Socketwiz Bookmarks | 2/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the root_dir parameter. | |
| Modificada | Media (6.8) | 2.4% | — | Bluesocket BSC 2100 | 7/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.pl in BlueSocket Secure Controller (BSC) before 5.2, or without 5.1.1-BluePatch, allows remote attackers to inject arbitrary web script or HTML via the ad_name parameter. | |
| Modificada | Media (6.8) | 2.3% | — | Socketmail | 31/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) index.php and (2) inc-common.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Socketkb | 1/12/2005 | 16/6/2026 | PHP file include vulnerability in SocketKB 1.1.0 and earlier allows remote attackers to include arbitrary local files via the __f parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Socketkb | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in SocketKB 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) node and (2) art_id parameters. |