Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

159 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)3.7%—HP Storage Essentials SRM EnterpriseHP Storage Essentials SRM Standard12/2/200816/6/2026
Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors.
ModificadaMedia (5)0.78%—Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+105/11/200716/6/2026
Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature.
ModificadaMedia (4.3)1.1%—Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+105/11/200716/6/2026
Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP requests that trigger creation of a server-status page.
ModificadaMedia (5)2.2%—Hitachi Ucosminexus Application Server EnterpriseHitachi Ucosminexus Application Server StandardHitachi Ucosminexus ClientHitachi Ucosminexus Developer Professional+49/10/200716/6/2026
The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain SSL/TLS handshake requests. NOTE: this may be the same as…
ModificadaMedia (4.3)1.2%—Hitachi Cosminexus AgentHitachi Cosminexus Library StandardHitachi Cosminexus Library WEB9/10/200716/6/2026
Hitachi Cosminexus Agent 03-00 through 03-05, and Cosminexus Library Standard and Web Edition 04-00 and 04-01, might allow remote attackers to cause a denial of service (agent process crash) via invalid data from clients other than Cosminexus Manager.
ModificadaMedia (4.3)1.7%—Hitachi Ucosminexus Application Server EnterpriseHitachi Ucosminexus Application Server StandardHitachi Ucosminexus Developer StandardHitachi Ucosminexus Service Platform8/9/200716/6/2026
The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7.5 can generate HTML documents that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably the same issue as CVE-2007-3503.
ModificadaAlta (10)5.9%—Hitachi Ucosminexus Application Server EnterpriseHitachi Ucosminexus Application Server StandardHitachi Ucosminexus Service Platform8/9/200716/6/2026
Multiple buffer overflows in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.
ModificadaMedia (5)2.2%—Hitachi Ucosminexus Application Server EnterpriseHitachi Ucosminexus Application Server StandardHitachi Ucosminexus Service Platform8/9/200716/6/2026
Multiple unspecified vulnerabilities in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service via unspecified vectors.
ModificadaMedia (4.6)0.31%—Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+328/8/200716/6/2026
Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges.
ModificadaMedia (4.4)0.28%—Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+328/8/200716/6/2026
Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.
ModificadaMedia (4.4)0.33%—Suse LinuxSuse Linux Openexchange ServerSuse Linux School ServerSuse Linux Standard Server+314/5/200716/6/2026
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
ModificadaAlta (10)1.8%—Mailenable EnterpriseMailenable Standard12/2/200716/6/2026
Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 leads to "weakened authentication security" with unknown impact and attack vectors. NOTE: due to lack of details, it is not clear whether this is the…
ModificadaAlta (7.5)1.3%💥 ExploitNoname Media Photo Galerie Standard6/2/200716/6/2026
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)1.2%—Hitachi Cosminexus Application ServerHitachi Cosminexus Application Server Version 5Hitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+1526/1/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps.
ModificadaAlta (10)5.9%—Mailenable EnterpriseMailenable ProfessionalMailenable Standard19/12/200616/6/2026
Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprise 1.41, and 2.35 and earlier before ME-10026 allows remote attackers to execute arbitrary code via a long argument to the PASS command.
ModificadaMedia (5)3.5%—Mailenable EnterpriseMailenable ProfessionalMailenable Standard7/9/200616/6/2026
SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via an SPF lookup for a domain with a large number of records, which triggers a null pointer exception.
ModificadaAlta (10)1.8%—Mailenable EnterpriseMailenable ProfessionalMailenable Standard15/4/200616/6/2026
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to "authentication exploits". NOTE: this is a different set of affected versions, and probably a different…
ModificadaBaja (2.6)1.6%—Smithmicro Stuffit DeluxeSmithmicro Stuffit ExpanderSmithmicro Stuffit StandardSmithmicro Zipmagic Deluxe28/2/200616/6/2026
Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.
ModificadaMedia (5)1.5%—Hitachi JPI Netsight II Port Discovery AdvanceHitachi JPI Netsight II Port Discovery Standard21/1/200616/6/2026
Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".
ModificadaMedia (6.4)1.2%—Suse Linux Openexchange ServerSuse Linux School ServerSuse Linux Standard ServerSuse Sled Beagle+131/12/200516/6/2026
liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013.
ModificadaMedia (5)1.2%—Standards Based Linux Instrumentation Sblim-sfcb5/10/200516/6/2026
httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service (resource consumption) by connecting to sblim-sfcb but not sending any data.
ModificadaMedia (5)1.6%—Standards Based Linux Instrumentation Sblim-sfcb5/10/200516/6/2026
httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service via long HTTP headers.
ModificadaAlta (10)4.2%—Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+213/7/200516/6/2026
The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the…
ModificadaMedia (5)51%—Mailenable ProfessionalMailenable Standard12/7/200516/6/2026
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.
ModificadaMedia (5)4.2%💥 ExploitMailenable Standard2/5/200516/6/2026
Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field.
Orbitaley — Vulnerabilidades