Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
–

1674 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)7.3%💥 ExploitWorking Resources Inc. Badblue31/12/200216/6/2026
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.
ModificadaAlta (7.5)2.7%—Working Resources Inc. Badblue4/10/200216/6/2026
BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges.
ModificadaMedia (5)3.2%💥 ExploitWorking Resources Inc. Badblue4/10/200216/6/2026
BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.
ModificadaMedia (5)3.2%💥 ExploitWorking Resources Inc. Badblue4/10/200216/6/2026
BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.
ModificadaMedia (5)1.6%—Working Resources Inc. Badblue12/8/200216/6/2026
BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end.
ModificadaMedia (5)38%💥 ExploitWorking Resources Inc. Badblue25/6/200216/6/2026
Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.
ModificadaAlta (7.5)1.6%—Working Resources Inc. Badblue25/6/200216/6/2026
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.
ModificadaBaja (2.6)1.3%—Open Source Development Network Slashcode31/5/200216/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en Slash anteriores a 2.2.5, como los usados en Slashcode y otros sitios, permite a atacantes remotos robar cookies e información de autentificación de otros usuarios, mediante Javascript en una URL, probablemente en el campo formkey.
ModificadaMedia (4.6)0.35%—Open Source Development Network Slashcode31/12/200116/6/2026
Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack.
ModificadaAlta (7.2)0.53%—HP Process Resource Manager31/8/200116/6/2026
Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.
ModificadaMedia (5)3.7%💥 ExploitMimanet Source Viewer22/8/200116/6/2026
Directory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the 'loc' variable.
ModificadaMedia (5)2.3%—Working Resources Inc. Badblue22/8/200116/6/2026
BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.
ModificadaAlta (10)11%💥 ExploitWorking Resources Inc. Badblue3/5/200116/6/2026
Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.
ModificadaAlta (7.5)1.8%—Sourceforge Newsdaemon3/5/200116/6/2026
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.
ModificadaMedia (6.4)3.5%💥 ExploitWorking Resources Inc. Badblue3/5/200116/6/2026
ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.
ModificadaAlta (10)4.0%—Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+1112/3/200116/6/2026
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
ModificadaAlta (7.5)2.2%—Open Source Development Network Slashcode11/12/200016/6/2026
The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly execute arbitrary commands.
ModificadaAlta (7.2)0.87%💥 ExploitTech-source Raptor GFX Pgx3220/10/200016/6/2026
Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.
ModificadaAlta (7.2)0.44%—Tech-source Raptor GFX Pgx3220/10/200016/6/2026
pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack.
ModificadaAlta (7.2)1.0%💥 ExploitTech-source Raptor GFX Pgx3220/10/200016/6/2026
pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program.
ModificadaBaja (1.2)0.26%—Cisco Resource Manager31/12/199916/6/2026
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.
ModificadaBaja (2.1)0.36%—Cisco Resource Manager31/12/199916/6/2026
Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names…
ModificadaAlta (7.5)5.8%—Microsoft Backoffice Resource KIT22/2/199916/6/2026
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
ModificadaAlta (10)5.2%—FMS Inc. Total VB SourcebookMicrosoft Access1/1/199916/6/2026
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
Orbitaley — Vulnerabilidades