Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1460 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.9%💥 ExploitThomas Rybak Minigal 22/11/200516/6/2026
MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.
ModificadaAlta (7.5)3.1%—SUN Java System Directory Proxy ServerSUN Java System Directory ServerSUN ONE Administration ServerSUN ONE Directory Server20/10/200516/6/2026
Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2…
ModificadaAlta (7.5)21%💥 ExploitDameware Development Mini Remote Control Server8/9/200516/6/2026
Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary code via the username.
ModificadaMedia (4.6)0.59%—Raritan Dominion SX4 FirmwareRaritan Dominion SX8 FirmwareRaritan Dominion Sx16 FirmwareRaritan Dominion Sx32 Firmware+15/7/200516/6/2026
Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.
ModificadaAlta (7.2)0.35%—Dameware Development Mini Remote ControlDameware Development NT Utilities2/5/200516/6/2026
Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.
ModificadaBaja (2.1)0.35%—Dameware Development Dameware NT UtilitiesDameware Development Miniremote Control2/5/200516/6/2026
The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain sensitive information.
ModificadaMedia (5)1.9%—Minis2/5/200516/6/2026
Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.
ModificadaMedia (5)1.4%—Novell Ichain Mini FTP ServerAI15/3/200516/6/2026
Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.
ModificadaMedia (5)1.7%—Minis16/1/200516/6/2026
minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.
ModificadaMedia (4.6)9.7%💥 ExploitMicrosoft Zero Administration KIT7/1/200516/6/2026
ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.
ModificadaMedia (5)1.5%—Minihttpserver.net WEB Forums Server31/12/200416/6/2026
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).
ModificadaMedia (4.3)0.94%—Minihttpserver.net Forum WEB Server31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm.
ModificadaAlta (7.5)2.6%💥 ExploitMinibb31/12/200416/6/2026
SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.
ModificadaMedia (4.6)0.31%—Minihttpserver.net WEB Forums ServerAI31/12/200416/6/2026
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.
ModificadaAlta (10)5.6%💥 ExploitDell Truemobile 1300 Wlan Mini-pci Card Util Trayapplet31/12/200416/6/2026
Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.
ModificadaAlta (7.5)72%💥 ExploitMinishare Minimal Http Server31/12/200416/6/2026
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaMedia (5)3.8%💥 ExploitMinishare Minimal Http Server26/5/200416/6/2026
MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.
ModificadaAlta (7.5)1.1%—Dameware Development Mini Remote Control Server24/3/200416/6/2026
Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.
ModificadaMedia (5)0.84%—Solarwinds Dameware Mini Remote Control23/3/200416/6/2026
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
ModificadaAlta (7.5)17%💥 ExploitDameware Development Mini Remote Control Server17/2/200416/6/2026
Desbordamiento de búfer en DameWare Mini Remote Control anteriores a 3.73 permite a atacantes remotos ejecutar código arbitrario mediante una petición de pre-autenticación muy larga al puerto TCP 6129.
ModificadaAlta (7.5)2.7%—Minimalist3/2/200416/6/2026
Vulnerabilidad desconocida en en el minimalist mailing list manager 2.4, 2.2, y posiblemente otras versiones, permite que atacantes remotos ejecuten comandos arbitrarios.
ModificadaMedia (6.8)1.2%—Visual Mining Netcharts Xbrl Server31/12/200316/6/2026
NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification.
ModificadaMedia (6.8)2.7%💥 ExploitGonicus System Administration31/12/200316/6/2026
PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5)…
ModificadaAlta (10)2.2%—Miniportal27/5/200316/6/2026
admin.php en miniPortail permite que atacantes remotos obtengan privilegios administrativos fijando la cookie miniPortailAdmin al valor ""adminok"".
ModificadaMedia (5)2.2%—Daniel Arenz Mini Server2/4/200316/6/2026
Vulnerabilidad de atravesamiento de directorios en Daniel Arenz Mini Server 2.1.6 permite a atacantes remotos leer ficheros arbitrarios mediante secuencias ../ (punto punto barra) o ..\\ (punto punto barra invertida)
Orbitaley — Vulnerabilidades