Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
149 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 2.8% | — | CA Identityminder | 26/12/2012 | 16/6/2026 | Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to execute arbitrary commands or modify data via unknown vectors. | |
| Modificada | Media (4.3) | 1.4% | — | CA Siteminder | 8/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.fcc in CA SiteMinder R6 SP6 before CR7 and R12 SP3 before CR8 allows remote attackers to inject arbitrary web script or HTML via the postpreservationdata parameter. | |
| Modificada | Media (4.3) | 2.4% | — | Broadcom SiteminderCA Siteminder | 27/4/2011 | 16/6/2026 | The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data. | |
| Modificada | Alta (7.2) | 0.75% | 💥 Exploit | Tukeva Password Reminder | 21/4/2010 | 16/6/2026 | TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection. | |
| Modificada | Media (4.3) | 4.4% | 💥 Exploit | SUN J2eeBroadcom Siteminder | 11/8/2009 | 16/6/2026 | CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters. | |
| Modificada | Baja (2.1) | 0.34% | — | Zoneminder | 27/4/2009 | 16/6/2026 | ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file. | |
| Modificada | Media (5) | 1.2% | — | Zoneminder | 27/4/2009 | 16/6/2026 | ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script. | |
| Modificada | Media (6.5) | 0.86% | 💥 Exploit | Plxwebdev PLX Auto Reminder | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action. | |
| Modificada | Media (4.3) | 1.0% | — | Scripts-for-sites EZ Reminder | 11/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in password.php in Scripts for Sites EZ Reminder allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Yourfreeworld Reminder Service Script | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 3.5% | — | Zoneminder | 2/9/2008 | 16/6/2026 | Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Zoneminder | 2/9/2008 | 16/6/2026 | SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via the filter array parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Zoneminder | 2/9/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified "zm_html_view_*.php" files. | |
| Modificada | Alta (7.5) | 2.5% | — | Zoneminder | 1/5/2008 | 16/6/2026 | ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Broadcom Etrust Siteminder | 10/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in CA (formerly Computer Associates) eTrust SiteMinder Agent allows remote attackers to inject arbitrary web script or HTML via the SMAUTHREASON parameter, a different vector than CVE-2005-2204. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (4.3) | 1.9% | — | Broadcom Etrust Siteminder | 11/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and… | |
| Modificada | Alta (10) | 5.0% | — | Netegrity Sideminder Affiliate Agent | 18/8/2004 | 16/6/2026 | Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Netegrity IdentityminderNetegrity Policy Server | 6/8/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Triornis Zoneminder | 14/6/2004 | 16/6/2026 | Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string. | |
| Modificada | Media (4.3) | 1.1% | — | Netegrity SiteminderAI | 31/12/2003 | 16/6/2026 | siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, reading Referer logs, or other methods. | |
| Modificada | Media (6.8) | 1.5% | — | Netegrity SiteminderAI | 31/12/2003 | 16/6/2026 | siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a URL that might trick users into visiting an arbitrary web site referenced by this parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Netegrity Siteminder | 24/8/2001 | 16/6/2026 | Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters. | |
| Modificada | Alta (7.5) | 1.7% | — | Netegrity Siteminder | 14/11/2000 | 16/6/2026 | Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL. |