Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

216 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)2.3%—Visual Mining Netcharts Server29/5/201517/6/2026
projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary files, and consequently execute them, via unspecified vectors.
ModificadaAlta (10)7.2%—Visualmining Netcharts Server29/5/201517/6/2026
Directory traversal vulnerability in saveFile.jsp in the development installation in Visual Mining NetChart allows remote attackers to write to arbitrary files via unspecified vectors.
ModificadaMedia (4.3)0.97%—Amcharts Flash28/12/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in amCharts Flash 1 allow remote attackers to inject arbitrary web script or HTML via the (1) data_file or (2) settings_file parameter to ampie.swf; the message element in the chart_data parameter to (3) amcolumn.swf, (4) amline.swf, (5) amradar.swf, or (6) amxy.sw;…
ModificadaMedia (5.4)0.27%—Smartstudy Pinkfong TV16/10/201417/6/2026
The PinkFong TV (aka kr.co.smartstudy.pinkfongtv_android_googlemarket) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Cocodigi Martial Arts Battle Card16/10/201417/6/2026
The Martial Arts Battle Card (aka com.tapenjoy.zjh.tw) application 1.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)1.1%—Decoracionesnailart Designs Nail Arts19/9/201417/6/2026
The Designs Nail Arts (aka com.decoracionesnailart.flickr) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5)19%💥 ExploitTera Charts Plugin Project Tera-charts11/7/201417/6/2026
Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.
ModificadaMedia (6.8)2.0%—Rimarts Becky! Internet Mail9/7/201417/6/2026
Buffer overflow in RimArts Becky! Internet Mail before 2.68 allows remote POP3 servers to execute arbitrary code via a crafted response.
ModificadaMedia (5.4)1.6%—EMC Smarts Network Configuration Manager1/7/201417/6/2026
Session fixation vulnerability in the Report Advisor (RA) component in EMC Network Configuration Manager (NCM) before 9.3 allows remote attackers to hijack web sessions via a session cookie.
ModificadaBaja (2.1)0.53%—HP Array Configuration UtilityHP Array Diagnostics UtilityHP Proliant Array DiagnosticsHP Smartssd Wear Gauge Utility12/4/201417/6/2026
Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and SmartSSD Wear Gauge Utility 9.40 and earlier allows local users to gain privileges via unknown vectors.
ModificadaMedia (5.8)1.4%—Skyarts Neofiler12/1/201417/6/2026
Directory traversal vulnerability in the NeoFiler application 5.4.3 and earlier, NeoFiler Free application 5.4.3 and earlier, and NeoFiler Lite application 2.4.2 and earlier for Android allows attackers to overwrite or create arbitrary files via unspecified vectors.
ModificadaMedia (4)1.2%—EMC RSA Archer EgrcEMC RSA Archer Smartsuite7/5/201316/6/2026
EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allows remote authenticated users to bypass intended access restrictions and modify global reports via unspecified vectors.
ModificadaMedia (4.3)0.94%—EMC RSA Archer EgrcEMC RSA Archer Smartsuite7/5/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4)1.2%—EMC RSA Archer EgrcEMC RSA Archer Smartsuite7/5/201316/6/2026
EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allows remote authenticated users to bypass intended access restrictions and upload arbitrary files via unspecified vectors.
ModificadaAlta (9.3)1.2%—EMC Smarts Network Configuration Manager28/3/201316/6/2026
Multiple unspecified vulnerabilities in the System Management (aka SysAdmin) Console in EMC Smarts Network Configuration Manager (NCM) through 9.2 have unknown impact and attack vectors, a different issue than CVE-2013-0935. NOTE: this might overlap CVEs for open-source server components or other third-party…
ModificadaMedia (4.3)0.94%—EMC Smarts IP ManagerEMC Smarts Mpls ManagerEMC Smarts Network Protocol ManagerEMC Smarts Server Manager+228/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in EMC Smarts IP Manager, Smarts Service Assurance Manager, Smarts Server Manager, Smarts VoIP Availability Manager, Smarts Network Protocol Manager, and Smarts MPLS Manager before 9.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaAlta (9.3)4.1%—EMC Smarts Network Configuration Manager28/3/201316/6/2026
EMC Smarts Network Configuration Manager (NCM) before 9.2 does not require authentication for all Java RMI method calls, which allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (6.8)0.93%—EMC RSA Archer SmartsuiteEMC RSA Archer Egrc6/2/201316/6/2026
EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to conduct clickjacking attacks via a crafted web page.
ModificadaMedia (6.5)2.1%—EMC RSA Archer SmartsuiteEMC RSA Archer Egrc6/2/201316/6/2026
Directory traversal vulnerability in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allows remote authenticated users to upload files, and consequently execute arbitrary code, via a relative path.
ModificadaAlta (7.5)1.4%—EMC RSA Archer SmartsuiteEMC RSA Archer Egrc6/2/201316/6/2026
The Silverlight cross-domain policy in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 does not restrict access to the Archer application, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
ModificadaMedia (4.3)1.4%—EMC RSA Archer SmartsuiteEMC RSA Archer Egrc6/2/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.9)0.40%—Nirsoft Smartsniff7/9/201216/6/2026
Untrusted search path vulnerability in SmartSniff 1.71 allows local users to gain privileges via a Trojan horse wpcap.dll file in the current working directory, as demonstrated by a directory that contains a .cfg or .ssp file. NOTE: some of these details are obtained from third party information.
ModificadaBaja (3.6)0.31%—Artsoft Rocks'n'diamonds15/12/201116/6/2026
Artsoft Entertainment Rocks'n'Diamonds (aka rocksndiamonds) 3.3.0.1 allows local users to overwrite arbitrary files via a symlink attack on .rocksndiamonds/cache/artworkinfo.cache under a user's home directory.
ModificadaAlta (9.3)8.6%💥 ExploitCursorarts Zipwrangler4/5/201016/6/2026
Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename.
ModificadaMedia (5)19%💥 ExploitRecly COM Smartsite3/5/201016/6/2026
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.