Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1385 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)45%💥 ExploitAvaya Converged Communications ServerRedhat Fedora CoreTrustix Secure LinuxAvaya Integrated Management+427/7/200416/6/2026
La función strip_tags en PHP 4.x hasta 4.3.7, y 5.x hasta 5.0.0RC3, no filtra caractéres null() dentro de nombreres de etiquetas cuanto se restringe la entrada a etiquetas permitidas, lo que permite que etiquetas peligrosas sean procesadas por navegadores como Internet Explorer y Safari, que ignoran caractéres nulos y…
ModificadaMedia (5)1.4%—Mitel 3300 Integrated Communications PlatformAI28/2/200416/6/2026
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.
ModificadaAlta (7.5)3.8%—Nortel Business Communications ManagerNortel 802.11 Wireless IP GatewayNortel Succession Communication Server 100017/2/200416/6/2026
Múltiples vulnerabilidades en la implementación del protocolo H.323 en Nortel Networks Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, y 802.11 Wireless IP Gateway permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario, como se demostró…
ModificadaAlta (7.5)7.6%—Apache Http ServerApache MOD Digest AppleAvaya Communication ManagerAvaya Intuity Audix LX+103/2/200416/6/2026
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
ModificadaMedia (5)2.0%—Whale Communications E-gap31/12/200316/6/2026
Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor.
ModificadaAlta (7.5)4.7%—Nortel Succession Communication Server 200031/12/200316/6/2026
The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
ModificadaMedia (6.8)4.3%💥 ExploitSnitz Communications Snitz Forums 20007/8/200316/6/2026
Vulnerabilidad de secuencias de comandos (XSS) en search.asp de Snitz Forums 3.4.03 y anteriores permite a atacantes remotos ejecutar script web arbitrario mediante el parámetro Search.
ModificadaAlta (10)3.8%—Snitz Communications Snitz Forums 20007/8/200316/6/2026
password.asp en Snitz Forums 3.4.03 y anteriores permite a atacantes remotos reestablecer contraseñas y ganar privilegios de otros usuarios mediante una petición directa a password.asp con un identificador (id) de miembro modificado.
ModificadaAlta (10)1.8%—Snitz Communications Snitz Forums 20007/8/200316/6/2026
Snitz Forums 3.4.03 y anteriores permite a atacantes ganar privilegios como otros usuarios robando y reutlizando la contraseña cifrada después de haber obtenido un identificador de sesión válido.
ModificadaAlta (7.5)2.4%—Snitz Communications Snitz Forums 200016/6/200316/6/2026
Vulnerabilidad de inyección de SQL en Snitz Forums 2000 anteriores a la 3.3.03 permite que atacantes remotos ejecuten procedimientos almacenados arbitrarios mediante la variable Email.
ModificadaMedia (6.4)2.0%—Netscape Communicator31/12/200216/6/2026
Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.
ModificadaAlta (10)5.8%—Netscape Communicator31/12/200216/6/2026
Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.
ModificadaMedia (5)1.9%—Blue World Communications Lasso WEB Data Engine31/12/200216/6/2026
Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL.
ModificadaMedia (5)1.6%—MozillaNetscape CommunicatorNetscape Navigator31/12/200216/6/2026
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
ModificadaMedia (4.6)1.0%💥 ExploitNetscape Communicator31/12/200216/6/2026
Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.
ModificadaMedia (5)1.1%—Netscape Communicator31/12/200216/6/2026
Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself.
ModificadaMedia (5)3.9%💥 ExploitMozillaNetscape CommunicatorNetscape Navigator31/12/200216/6/2026
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
ModificadaMedia (5)1.3%—Netscape Communicator29/11/200216/6/2026
Netscape Communicator 4.x permite a atacantes usar un enlace para robar las preferencias de un usuario, incluyendo información potencialmente sensible como historia de URLs, direcciones de correo electrónico, y posiblemente sus contraseñas, mediante la redefinición de la función user_pref() y accediendo al fichero…
ModificadaAlta (10)2.1%💥 ExploitRuslan Communications Body Builder4/10/200216/6/2026
SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password.
ModificadaMedia (5)8.3%💥 ExploitNEW Atlanta Communications Servletexec Isapi4/10/200216/6/2026
Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences.
ModificadaMedia (5)7.6%💥 ExploitNEW Atlanta Communications Servletexec Isapi4/10/200216/6/2026
The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message.
ModificadaMedia (5)3.3%💥 ExploitNEW Atlanta Communications Servletexec Isapi4/10/200216/6/2026
NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long URL sent directly to com.newatlanta.servletexec.JSP10Servlet.
ModificadaAlta (7.5)4.9%💥 ExploitSnitz Communications Snitz Forums 200025/6/200216/6/2026
Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag.
ModificadaMedia (4.6)0.43%—Hotline Communications Hotline Connect25/6/200216/6/2026
Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.
ModificadaAlta (7.5)3.5%—MozillaNetscape CommunicatorNetscape Navigator18/6/200216/6/2026
Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.