Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | Plumtree Corporate Portal | 16/5/2002 | 16/6/2026 | Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter. | |
| Modificada | Media (6.4) | 1.6% | — | ACD Incorporated Cwpapi | 16/5/2002 | 16/6/2026 | GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root. | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | ImmunixMandrakesoft Mandrake Single Network FirewallOpenbsd OpensshOpenpkg+7 | 15/3/2002 | 16/6/2026 | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | |
| Modificada | Alta (7.5) | 7.8% | — | Apache Http ServerMandrakesoft Mandrake Single Network FirewallMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server | 28/11/2001 | 16/6/2026 | The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories. | |
| Modificada | Baja (2.1) | 0.81% | 💥 Exploit | ImmunixUniversity OF Washington PineEngardelinux Secure LinuxMandrakesoft Mandrake Linux+2 | 18/10/2001 | 16/6/2026 | Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Alta (7.5) | 1.4% | — | PGP Corporate DesktopPGP E-business ServerPGP FreewarePGP Personal Security+1 | 4/9/2001 | 16/6/2026 | PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by… | |
| Modificada | Alta (7.5) | 2.0% | — | Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+4 | 18/7/2001 | 16/6/2026 | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning. | |
| Modificada | Media (5) | 4.1% | — | Mandrakesoft Mandrake Single Network FirewallOpenldapDebian LinuxMandrakesoft Mandrake Linux+2 | 16/7/2001 | 16/6/2026 | slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field. | |
| Modificada | Alta (7.5) | 2.4% | — | LicqConectiva LinuxFreebsdMandrakesoft Mandrake Linux+2 | 2/7/2001 | 16/6/2026 | licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |
| Modificada | Alta (7.5) | 2.7% | — | Debian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Linux | 27/6/2001 | 16/6/2026 | Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header. | |
| Modificada | Alta (7.2) | 0.86% | 💥 Exploit | Debian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server | 3/5/2001 | 16/6/2026 | Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges. | |
| Modificada | Baja (2.1) | 0.36% | — | Conectiva LinuxCaldera Openlinux EdesktopMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+1 | 26/3/2001 | 16/6/2026 | kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges. | |
| Modificada | Baja (2.1) | 0.86% | 💥 Exploit | Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat LinuxTrustix Secure Linux+1 | 26/3/2001 | 16/6/2026 | When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib. | |
| Modificada | Baja (1.2) | 0.30% | — | ExmhDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server | 12/3/2001 | 16/6/2026 | exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file. | |
| Modificada | Baja (1.2) | 0.30% | — | ImmunixDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+1 | 12/3/2001 | 16/6/2026 | privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Baja (1.2) | 0.37% | — | ImmunixMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Linux+1 | 12/3/2001 | 16/6/2026 | sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack. | |
| Modificada | Media (5) | 1.9% | — | Itserv Incorporated Ridewaypn | 9/1/2001 | 16/6/2026 | The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests. | |
| Modificada | Media (5) | 1.6% | — | Csandt Corporatetime FOR THE WEB | 11/12/2000 | 16/6/2026 | CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server. |