Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.2% | — | Novell Data SynchronizerNovell Mobility Pack | 9/8/2011 | 16/6/2026 | WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Media (4.3) | 1.2% | — | Novell Data SynchronizerNovell Mobility Pack | 9/8/2011 | 16/6/2026 | The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. | |
| Modificada | Media (5) | 1.4% | — | Novell Data SynchronizerNovell Mobility Pack | 9/8/2011 | 16/6/2026 | The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (4.3) | 1.2% | — | Novell Data SynchronizerNovell Mobility Pack | 9/8/2011 | 16/6/2026 | Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (5) | 1.4% | — | Novell Data SynchronizerNovell Mobility Pack | 9/8/2011 | 16/6/2026 | The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensitive GroupWise information via unspecified vectors. | |
| Modificada | Media (5.5) | 1.3% | — | Novell Data SynchronizerNovell Mobility Pack | 9/6/2011 | 16/6/2026 | Unspecified vulnerability in the Mobility Pack 1.1.2 and earlier in Novell Data Synchronizer 1.0.x, and 1.1.x through 1.1.1 build 428, allows remote authenticated users to access the accounts of other users via unknown vectors. | |
| Modificada | Alta (7.2) | 0.31% | — | Cisco Anyconnect Secure Mobility Client | 2/6/2011 | 16/6/2026 | The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain privileges via unspecified user-interface interaction, aka Bug ID CSCta40556. | |
| Modificada | Alta (9.3) | 11% | — | Cisco Anyconnect Secure Mobility Client | 2/6/2011 | 16/6/2026 | The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linux and Mac OS X downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the… | |
| Modificada | Alta (7.6) | 70% | 💥 Exploit | Cisco Anyconnect Secure Mobility Client | 2/6/2011 | 16/6/2026 | The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to… | |
| Modificada | Alta (8.3) | 1.9% | — | HP Procurve Access Point SoftwareHP Procurve M110 Access PointHP Procurve Miltope Dual Radio Access PointHP Procurve Msm310-r Access Point+14 | 18/10/2010 | 16/6/2026 | Unspecified vulnerability on HP ProCurve Access Points, Access Controllers, and Mobility Controllers with software 5.1.x through 5.1.9, 5.2.x through 5.2.7, 5.3.x through 5.3.5, and 5.4.x through 5.4.0 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (6.1) | 0.91% | — | Arubanetworks ArubaosArubanetworks Aruba Mobility Controller | 2/11/2009 | 16/6/2026 | ArubaOS 3.3.1.x, 3.3.2.x, RN 3.1.x, 3.4.x, and 3.3.2.x-FIPS on the Aruba Mobility Controller allows remote attackers to cause a denial of service (Access Point crash) via a malformed 802.11 Association Request management frame. | |
| Modificada | Alta (7.8) | 1.4% | — | Arubanetworks Aruba Mobility ControllerArubanetworks Arubaos | 27/8/2009 | 16/6/2026 | The SNMP daemon in ArubaOS 3.3.2.6 in Aruba Mobility Controller does not restrict SNMP access, which allows remote attackers to (1) read all SNMP community strings via SNMP-COMMUNITY-MIB::snmpCommunityName (1.3.6.1.6.3.18.1.1.1.2) or SNMP-VIEW-BASED-ACM-MIB::vacmGroupName (1.3.6.1.6.3.16.1.2.1.3) with knowledge of one… | |
| Modificada | Alta (10) | 1.8% | — | Arubanetworks Aruba Mobility ControllerArubanetworks Arubaos | 21/8/2009 | 16/6/2026 | Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security… | |
| Modificada | Alta (7.8) | 2.1% | — | Aruba Networks Aruba Mobility ControllerAruba Networks Aruba Mobility ControllersArubanetworks Aruba Mobility Controller | 15/12/2008 | 16/6/2026 | Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.x, 3.1.x, 3.2.x, 3.3.1.x, and 3.3.2.x allows remote attackers to cause a denial of service (device crash) via a malformed Extensible Authentication Protocol (EAP) frame. | |
| Modificada | Media (4.3) | 1.2% | — | Aruba Networks Aruba Mobility Controller | 16/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.5.x, 2.5.6.x, 3.1.1.x, 3.2.0.x, and 3.3.1.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 5.1% | — | Cisco Emergency ResponderCisco Mobility ManagerCisco Unified Communications ManagerCisco Unified Presence | 4/4/2008 | 16/6/2026 | The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which… | |
| Modificada | Media (6.8) | 1.3% | — | Aruba Networks Aruba Mobility Controllers | 9/1/2008 | 16/6/2026 | Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.11-FIPS or earlier allows remote attackers to bypass authentication mechanisms and obtain management or VPN interface access. | |
| Modificada | Alta (7.5) | 1.7% | — | BEA Weblogic Mobility Server | 15/12/2007 | 16/6/2026 | Unspecified vulnerability in the Image Converter functionality in BEA WebLogic Mobility Server 3.3, 3.5, and 3.6 through 3.6 SP1 allows remote attackers to obtain application file and resource access via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | Aruba Mobility Controller | 26/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login CGI program in Aruba Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier FIPS versions, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 6.1% | — | Alcatel-lucent Omniaccess WirelessAruba Mobility Controller | 14/2/2007 | 16/6/2026 | Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings. | |
| Modificada | Alta (7.5) | 2.3% | — | Alcatel-lucent Omniaccess WirelessAruba Mobility Controller | 14/2/2007 | 16/6/2026 | The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN. | |
| Modificada | Baja (2.1) | 0.31% | — | Globetrotter Mobility Manager | 29/1/2007 | 16/6/2026 | The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or grabbing periodic screenshots. | |
| Modificada | Media (4.6) | 0.32% | — | Trust Digital Trusted Mobility SuiteAI | 31/12/2005 | 16/6/2026 | Trusted Mobility Agent PC Policy in Trust Digital Trusted Mobility Suite provides a cancel button that bypasses the domain-authentication prompt, which allows local users to sync a handheld (PDA) device despite a policy setting that sync is unauthorized. |