Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 6.3% | — | HP Release Control | 30/5/2016 | 17/6/2026 | The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | |
| Modificada | Alta (7.8) | 3.4% | — | Cisco Headend System Release | 6/7/2015 | 17/6/2026 | Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91854. | |
| Modificada | Alta (7.8) | 3.4% | — | Cisco Headend System Release | 30/6/2015 | 17/6/2026 | Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91838. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Videoscape ConductorCisco Headend Digital Broadband Delivery SystemCisco Headend System Release | 30/5/2015 | 17/6/2026 | Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408. | |
| Modificada | Media (5) | 1.9% | — | Cisco Headend Digital Broadband Delivery SystemCisco Headend System Release | 30/5/2015 | 17/6/2026 | Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, via a crafted header in an HTTP request, aka Bug ID CSCus44909. | |
| Modificada | Alta (7.8) | 3.4% | — | Cisco DTA Control SystemCisco Headend Digital Broadband Delivery SystemCisco Headend System Release | 30/5/2015 | 17/6/2026 | Cisco DTA Control System (DTACS) 4.0.0.9 and Cisco Headend System Release allow remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCus50642, CSCus50662, CSCus50625, CSCus50657, and CSCus68315. | |
| Modificada | Media (5) | 2.0% | — | Cisco Headend Digital Broadband Delivery SystemCisco Headend System Release | 30/5/2015 | 17/6/2026 | Cisco Headend System Release allows remote attackers to cause a denial of service (DHCP and TFTP outage) via a flood of crafted UDP traffic, aka Bug ID CSCus04097. | |
| Modificada | Media (6.5) | 1.6% | — | Broadcom Release Automation | 16/12/2014 | 17/6/2026 | SQL injection vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote authenticated users to execute arbitrary SQL commands via a crafted query. | |
| Modificada | Media (4.3) | 1.8% | — | Broadcom Release Automation | 16/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.92% | — | Broadcom Release Automation | 16/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Alta (9) | 3.6% | — | HP Release Control | 28/6/2014 | 17/6/2026 | Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to gain privileges via unknown vectors. | |
| Modificada | Media (4) | 6.8% | 💥 Exploit | HP Release Control | 28/6/2014 | 17/6/2026 | Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sensitive information via unknown vectors. | |
| Modificada | Alta (9) | 6.8% | — | Xangati Software ReleaseXangati XNR | 15/4/2014 | 17/6/2026 | Xangati XSR before 11 and XNR before 7 allows remote attackers to execute arbitrary commands via shell metacharacters in a gui_input_test.pl params parameter to servlet/Installer. | |
| Modificada | Alta (7.8) | 5.9% | 💥 Exploit | Xangati Software ReleaseXangati XNR | 15/4/2014 | 17/6/2026 | Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the file parameter in a getUpgradeStatus action to servlet/MGConfigData, (2) the download parameter in a download action to servlet/MGConfigData, (3) the… | |
| Modificada | Media (6.2) | 0.44% | — | Fedora Project Fedora Release RawhideRedhat Enterprise Linux | 22/2/2013 | 16/6/2026 | A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use… | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | V-eva Press Release Script | 23/11/2011 | 16/6/2026 | SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 1.5% | — | DokeosDokeos Community Release | 10/5/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.0.3, allow remote attackers to execute arbitrary PHP code via a URL in the (1) rootSys and (2) clarolineRepositorySys parameters, and possibly the (3) lang_path, (4)… | |
| Modificada | Alta (10) | 3.8% | — | Jdedwards Enterpriseone ToolsOneworld ToolsOracle Application ServerOracle Collaboration Suite+8 | 20/4/2006 | 16/6/2026 | Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01. |