Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

162 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)3.1%—Gopivotal Grails-resourcesGopivotal Grails15/4/201417/6/2026
Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability…
ModificadaMedia (5)1.4%—Gopivotal Grails-resourcesGopivotal Grails15/4/201417/6/2026
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to files in the META-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this issue was SPLIT from CVE-2014-0053 due to…
ModificadaMedia (5)2.0%—Gopivotal Grails-resourcesGopivotal Grails15/4/201417/6/2026
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this identifier has been SPLIT due to different…
ModificadaMedia (4.9)0.95%—Cluster Resources Torque Resource ManagerClusterresources Torque Resource Manager13/1/201216/6/2026
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.
ModificadaMedia (5)1.4%—Montala Resourcespace19/11/201116/6/2026
ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors.
ModificadaAlta (7.5)2.9%—Clusterresources Torque Resource Manager15/8/201116/6/2026
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBS_O_HOST variable to the qsub program.
ModificadaAlta (8.5)2.5%—Clusterresources Torque Resource Manager24/6/201116/6/2026
Multiple buffer overflows in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.x before 2.4.14, 2.5.x before 2.5.6, and 3.x before 3.0.2 allow (1) remote authenticated users to gain privileges via a long Job_Name field in a qsub command to the server, and might allow (2) local users to…
ModificadaMedia (4.3)0.85%—Fr.simon Rundell PD Resources22/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.0%—Fr.simon Rundell PD Resources22/12/200916/6/2026
SQL injection vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.2%💥 ExploitW2B Phphotresources16/4/200816/6/2026
SQL injection vulnerability in cat.php in W2B phpHotResources allows remote attackers to execute arbitrary SQL commands via the kind parameter.
ModificadaAlta (7.5)1.1%—Easebay Resources Login Manager22/1/200716/6/2026
SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter.
ModificadaMedia (6.8)1.2%—Easebay Resources Login Manager22/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
ModificadaMedia (6.8)1.2%—Easebay Resources Paypal Subscription Manager22/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter.
ModificadaAlta (7.5)1.2%—Easebay Resources Paypal Subscription Manager22/1/200716/6/2026
SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
ModificadaAlta (7.2)0.34%—Cluster Resources Torque Resource Manager3/11/200616/6/2026
resmom/start_exec.c in pbs_mom in TORQUE Resource Manager 2.0.0p8 and earlier allows local users to create arbitrary files via a symlink attack on (1) a job output file in /usr/spool/PBS/spool and possibly (2) a job file in /usr/spool/PBS/mom_priv/jobs.
ModificadaAlta (7.5)1.5%—Asp-dev ASP Resources Forum11/12/200516/6/2026
Multiple SQL injection vulnerabilities in ASP-DEV ASP Resources Forum allow remote attackers to execute arbitrary SQL commands via the (1) forum_id parameter to forum.asp, (2) unspecified parameters to register.asp, and (3) the "Search For" field in search.asp.
ModificadaMedia (4.6)1.8%—Data Center Resources Avocent20/9/200516/6/2026
Avocent CCM console server running firmware 2.1 CCM4850 allows remote authenticated attackers to bypass port restrictions by connecting to the server via SSH and using the connect command to access the serial port.
ModificadaAlta (7.5)60%💥 ExploitWorking Resources Inc. Badblue2/5/200516/6/2026
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.
ModificadaMedia (5)2.8%💥 ExploitWorking Resources Inc. Badblue31/12/200416/6/2026
BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML.
ModificadaMedia (5)3.1%💥 ExploitWorking Resources Inc. Badblue20/8/200416/6/2026
BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.
ModificadaAlta (7.6)7.0%💥 ExploitWorking Resources Inc. Badblue9/6/200316/6/2026
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.
ModificadaAlta (7.5)1.5%—Working Resources Inc. Badblue31/3/200316/6/2026
BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).
ModificadaMedia (5)4.9%—Deerfield D2gfxWorking Resources Inc. Badblue31/12/200216/6/2026
Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents.
ModificadaMedia (4.3)7.3%💥 ExploitWorking Resources Inc. Badblue31/12/200216/6/2026
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.
ModificadaMedia (4.3)1.7%💥 ExploitWorking Resources Inc. Badblue31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.