Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 3.7% | — | HP Storage Essentials SRM EnterpriseHP Storage Essentials SRM Standard | 12/2/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors. | |
| Modificada | Media (5) | 0.78% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+10 | 5/11/2007 | 16/6/2026 | Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature. | |
| Modificada | Media (4.3) | 1.1% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+10 | 5/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP requests that trigger creation of a server-status page. | |
| Modificada | Media (5) | 2.2% | — | Hitachi Ucosminexus Application Server EnterpriseHitachi Ucosminexus Application Server StandardHitachi Ucosminexus ClientHitachi Ucosminexus Developer Professional+4 | 9/10/2007 | 16/6/2026 | The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain SSL/TLS handshake requests. NOTE: this may be the same as… | |
| Modificada | Media (4.3) | 1.2% | — | Hitachi Cosminexus AgentHitachi Cosminexus Library StandardHitachi Cosminexus Library WEB | 9/10/2007 | 16/6/2026 | Hitachi Cosminexus Agent 03-00 through 03-05, and Cosminexus Library Standard and Web Edition 04-00 and 04-01, might allow remote attackers to cause a denial of service (agent process crash) via invalid data from clients other than Cosminexus Manager. | |
| Modificada | Media (4.3) | 1.7% | — | Hitachi Ucosminexus Application Server EnterpriseHitachi Ucosminexus Application Server StandardHitachi Ucosminexus Developer StandardHitachi Ucosminexus Service Platform | 8/9/2007 | 16/6/2026 | The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7.5 can generate HTML documents that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably the same issue as CVE-2007-3503. | |
| Modificada | Alta (10) | 5.9% | — | Hitachi Ucosminexus Application Server EnterpriseHitachi Ucosminexus Application Server StandardHitachi Ucosminexus Service Platform | 8/9/2007 | 16/6/2026 | Multiple buffer overflows in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5) | 2.2% | — | Hitachi Ucosminexus Application Server EnterpriseHitachi Ucosminexus Application Server StandardHitachi Ucosminexus Service Platform | 8/9/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Media (4.6) | 0.31% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+3 | 28/8/2007 | 16/6/2026 | Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges. | |
| Modificada | Media (4.4) | 0.28% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+3 | 28/8/2007 | 16/6/2026 | Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges. | |
| Modificada | Media (4.4) | 0.33% | — | Suse LinuxSuse Linux Openexchange ServerSuse Linux School ServerSuse Linux Standard Server+3 | 14/5/2007 | 16/6/2026 | xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems. | |
| Modificada | Alta (10) | 1.8% | — | Mailenable EnterpriseMailenable Standard | 12/2/2007 | 16/6/2026 | Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 leads to "weakened authentication security" with unknown impact and attack vectors. NOTE: due to lack of details, it is not clear whether this is the… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Noname Media Photo Galerie Standard | 6/2/2007 | 16/6/2026 | SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 1.2% | — | Hitachi Cosminexus Application ServerHitachi Cosminexus Application Server Version 5Hitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+15 | 26/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps. | |
| Modificada | Alta (10) | 5.9% | — | Mailenable EnterpriseMailenable ProfessionalMailenable Standard | 19/12/2006 | 16/6/2026 | Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprise 1.41, and 2.35 and earlier before ME-10026 allows remote attackers to execute arbitrary code via a long argument to the PASS command. | |
| Modificada | Media (5) | 3.5% | — | Mailenable EnterpriseMailenable ProfessionalMailenable Standard | 7/9/2006 | 16/6/2026 | SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via an SPF lookup for a domain with a large number of records, which triggers a null pointer exception. | |
| Modificada | Alta (10) | 1.8% | — | Mailenable EnterpriseMailenable ProfessionalMailenable Standard | 15/4/2006 | 16/6/2026 | Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to "authentication exploits". NOTE: this is a different set of affected versions, and probably a different… | |
| Modificada | Baja (2.6) | 1.6% | — | Smithmicro Stuffit DeluxeSmithmicro Stuffit ExpanderSmithmicro Stuffit StandardSmithmicro Zipmagic Deluxe | 28/2/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive. | |
| Modificada | Media (5) | 1.5% | — | Hitachi JPI Netsight II Port Discovery AdvanceHitachi JPI Netsight II Port Discovery Standard | 21/1/2006 | 16/6/2026 | Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data". | |
| Modificada | Media (6.4) | 1.2% | — | Suse Linux Openexchange ServerSuse Linux School ServerSuse Linux Standard ServerSuse Sled Beagle+1 | 31/12/2005 | 16/6/2026 | liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013. | |
| Modificada | Media (5) | 1.2% | — | Standards Based Linux Instrumentation Sblim-sfcb | 5/10/2005 | 16/6/2026 | httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service (resource consumption) by connecting to sblim-sfcb but not sending any data. | |
| Modificada | Media (5) | 1.6% | — | Standards Based Linux Instrumentation Sblim-sfcb | 5/10/2005 | 16/6/2026 | httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service via long HTTP headers. | |
| Modificada | Alta (10) | 4.2% | — | Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+2 | 13/7/2005 | 16/6/2026 | The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the… | |
| Modificada | Media (5) | 51% | — | Mailenable ProfessionalMailenable Standard | 12/7/2005 | 16/6/2026 | Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication. | |
| Modificada | Media (5) | 4.2% | 💥 Exploit | Mailenable Standard | 2/5/2005 | 16/6/2026 | Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field. |