Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
134 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (1.9) | 0.30% | — | Dell EMC Unisphere | 2/11/2013 | 16/6/2026 | EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind password by reading the console. | |
| Modificada | Media (4.3) | 2.0% | — | Mark Theunissen Views Lang Switch | 5/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in theme/views_lang_switch.theme.inc in the Views Language Switcher module before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Unisoft COM Mycar | 3/6/2010 | 16/6/2026 | SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pagina parameter to index.php. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Unisoft COM Mycar | 3/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the modveh parameter to index.php. | |
| Modificada | Alta (10) | 5.2% | — | Unisys Business Information Server | 26/6/2009 | 16/6/2026 | Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitrary code via a crafted TCP packet. | |
| Modificada | Alta (7.6) | 2.2% | — | Nortel Communication Server 1000Nortel Unistim Protocol | 31/3/2009 | 16/6/2026 | Nortel UNIStim protocol, as used in Communication Server 1000 and other products, uses predictable sequence numbers, which allows remote attackers to hijack sessions via sniffing or brute force attacks. | |
| Modificada | Alta (7.8) | 3.8% | 💥 Exploit | Nortel Unistim IP Phone | 7/11/2008 | 16/6/2026 | Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: this issue could not be reproduced by a third party, who tested it on 0604DAD. In addition, the original researcher was not able to reliably reproduce the issue. | |
| Modificada | Alta (7.5) | 1.2% | — | Unisor CMS | 31/10/2006 | 16/6/2026 | SQL injection vulnerability in login.asp in UNISOR Content Management System (CMS) allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass fields. | |
| Modificada | Alta (7.8) | 2.0% | — | Unisys Clearpath MCP | 31/12/2002 | 16/6/2026 | The dynamic initialization feature of the ClearPath MCP environment allows remote attackers to cause a denial of service (crash) via a TCP port scan using a tool such as nmap. |