Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
1385 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | Nortel Communications Server | 30/5/2007 | 16/6/2026 | Vulnerabilidad no especificada en la tarjeta Nortel CS 1000 M en Enterprise VoIP-Core-CS 1000E, 1000M, y 1000S 04.50W anterior al 23/05/2007 en Meridian/CS 1000 permite a atacantes remotos provocar una denegación de servicio (cuelgue de la tarjeta) a través de vectores no especificados. | |
| Modificada | Media (6) | 1.4% | — | Avaya Communication Manager | 16/3/2007 | 16/6/2026 | Páginas web de mantenimiento no especificadas en Avaya S87XX, S8500, y S8300 versiones anteriores a CM 3.1.3, y Avaya SES permite a usuarios remotos autenticados ejecutar comandos de su elección mediante metacaracteres shell en vectores si especificar (también conocido como "inyección de comando shell"). | |
| Modificada | Baja (3.5) | 1.2% | — | Cisco ACS Solution EngineCiscoworksCisco IP CommunicatorCisco Meetingplace+14 | 16/3/2007 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en (1) PreSearch.html y (2) PreSearch.class en Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video… | |
| Modificada | Media (4.3) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 10/3/2007 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en pop_profile.asp de Snitz Forums 2000 3.4.06 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro MSN. NOTA: la procedencia de esta información es desconocida; los detalles se han obtenido… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 21/2/2007 | 16/6/2026 | Vulnerabilidad de inyección SQL en pop_profile.asp en Snitz Forums 2000 3.1 SR4 permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro id. | |
| Modificada | Alta (9) | 4.5% | 💥 Exploit | Centrality Communications Pa168 Chipset | 26/1/2007 | 16/6/2026 | La consola del web admin implementada por Centrality Communications (también conocido como Aredfox) PA168 chipset y firmware 1.54 y anteriores, en la manera prevista por varios teléfonos del IP, no requiere contraseñas o validación de tokens cuando se usa HTTP, lo cual permite a atacantes remotos conetar a un… | |
| Modificada | Crítica (9.8) | 1.4% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 30/10/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en pop_mail.asp en Snitz Forums 2000 3.4.06 permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro RC. NOTA: la procedencia de esta información es desconocida; los detalles se han obtenido de información de terceros. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | WEB Group Communication Center | 26/10/2006 | 16/6/2026 | Vulnerabilidad de inyección de SQL en quiz.php de Web Group Communication Center (WGCC) 0.5.6b y versiones anteriores, permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro qzid. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 14/9/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en forum.asp de Snitz Forums 2000 3.4.06 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante el parámetro sortorder. (variable strtopicsortord). | |
| Modificada | Baja (1.2) | 0.27% | — | NCP Network Communications Secure Client | 13/7/2006 | 16/6/2026 | NCP Secure Enterprise Client (también conocido como VPN/PKI client) 8.30 Build 59, y posiblemente anteriores versiones, cuando cuando el cortafuegos de enlace y el personal (Link FireWall y Personal FireWall) son ambos configurados para bloquear todo el tráfico de red de entrada y salida, permite a atacantes… | |
| Modificada | Alta (7.5) | 3.2% | — | Webex Communications Webex Downloader Activex Control | 7/7/2006 | 16/6/2026 | Múltiples desbordamientos de búfer en el control ActiveX WebEx Downloader, posiblemente versiones anteriores a Noviembre de 2005, permite a atacantes remotos ejecutar código de su elección a través de vectores no especificados. | |
| Modificada | Alta (9.3) | 8.7% | — | Webex Communications Downloader ActivexcontrolWebex Communications Downloader Java | 7/7/2006 | 16/6/2026 | WebEx Downloader ActiveX Control y WebEx Downloader Java anteriores a 2.1.0.0 no validan los componentes descargados, lo cual permite a atacantes remotos ejecutar código de su elección a través de sitios web que activan los controles ActiveX GpcUrlRoot y GpcIniFileName haciendo que el cliente se descargue un archivos… | |
| Modificada | Baja (2.6) | 1.2% | — | NEW Atlanta Communications Bluedragon ServerNEW Atlanta Communications Bluedragon Server JX | 26/6/2006 | 16/6/2026 | ulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en BlueDragon Server y Server JX v6.2.1.286 para Windows permite a atacantes remotos inyectar código web o HTML de su elección a través del nombre de fichero en una petición en un fichero (1) .cfm o (2) .cfml, que refleja el resultado en una página de… | |
| Modificada | Media (5) | 6.8% | 💥 Exploit | NEW Atlanta Communications Bluedragon ServerNEW Atlanta Communications Bluedragon Server JX | 26/6/2006 | 23/9/2026 | BlueDragon Server y Server JX v6.2.1.286 para Windows permite a atacantes remotos causar una denegación de servicio (cuelgue) a traves de una petición para un fichero .cfm cuyo nombre contiene un nombre de dispositivo MS-DOS como (1) con, (2) aux, (3) com1, y (4) com2. | |
| Modificada | Alta (7.5) | 1.5% | — | Snitz Communications Snitz Forums 2000 | 12/6/2006 | 16/6/2026 | SQL injection vulnerability in inc_header.asp in Snitz Forum 3.4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the %strCookieURL%.GROUP parameter in a cookie. | |
| Modificada | Media (5) | 1.6% | — | Snitz Communications Avatar MOD | 22/5/2006 | 16/6/2026 | avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product. | |
| Modificada | Media (5) | 1.3% | — | Kansok Communications Shopweezle | 11/4/2006 | 16/6/2026 | index.php in Shopweezle 2.0 allows remote attackers to include arbitrary local files via the url parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Kansok Communications Shopweezle | 11/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure… | |
| Modificada | Media (4.3) | 1.3% | — | Virtual Communication Services Vpmi Enterprise | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Service_Requests.asp in VPMi Enterprise 3.3 allows remote attackers to inject arbitrary web script or HTML via the Request_Name_Display parameter. | |
| Modificada | Baja (2.1) | 0.38% | — | NCP Network Communications Secure Client | 2/3/2006 | 16/6/2026 | NCP Network Communication Secure Client 8.11 Build 146 y posiblemente otras versiones, permite a usuarios locales provocar una denegación de servicio (consumo de CPU) a través de un número grande de argumentos para ncprwsnt.exe, posiblemente debido a un desbordamiento de buffer. | |
| Modificada | Baja (2.1) | 0.38% | — | NCP Network Communications Secure Client | 2/3/2006 | 16/6/2026 | NCP Network Communication Secure Client 8.11 Build 146 y posiblemente otras versiones, permite a usuarios locales provocar una denegación de servicio (uso de memoria y utilización de cpu) a través de una inundación de datagramas UDP arbitrarios de los puertos 0 a 65000. NOTA: este caso fue reportado como un… | |
| Modificada | Alta (7.2) | 0.42% | — | NCP Network Communications Secure Client | 2/3/2006 | 16/6/2026 | The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is automatically executed by the service after a connection is established. | |
| Modificada | Media (4.6) | 0.38% | — | NCP Network Communications Secure Client | 2/3/2006 | 16/6/2026 | NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass security protections and configure privileged options via a long argument to ncpmon.exe, which provides access to alternate privileged menus, possibly due to a buffer overflow. | |
| Modificada | Media (4.6) | 0.40% | — | NCP Network Communications Secure Client | 2/3/2006 | 16/6/2026 | Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program. | |
| Modificada | Alta (7.5) | 1.4% | — | Virtual Communication Services Vpmi Enterprise | 25/2/2006 | 16/6/2026 | SQL injection vulnerability in VCS Virtual Program Management Intranet (VPMi) Enterprise 3.3 allows remote attackers to execute arbitrary SQL commands via the UpdateID0 parameter to Service_Requests.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.… |