Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

1847 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)1.4%—Proofpoint Protection Server31/12/200416/6/2026
The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, which allows remote attackers to read or modify the backend database.
ModificadaMedia (4.6)0.43%—ISS Blackice PC Protection31/12/200416/6/2026
The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers.
ModificadaMedia (4.3)1.7%💥 ExploitProtector System31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web script or HTML via the (1) target or (2) portNum parameters.
ModificadaAlta (7.5)1.2%💥 ExploitProtector System31/12/200416/6/2026
SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using "/**/" sequences in the targeted fields.
ModificadaMedia (4.3)1.3%—WEB Animations Password Protect31/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.
ModificadaAlta (7.5)1.2%💥 ExploitWEB Animations Password Protect30/8/200416/6/2026
SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.
ModificadaBaja (2.1)0.43%—Pedestal Software Integrity Protection Driver17/8/200416/6/2026
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.
ModificadaAlta (7.1)0.85%💥 ExploitISS Blackice PC ProtectionISS Blackice Server Protection11/8/200416/6/2026
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall…
ModificadaAlta (7.5)1.4%—Protector System23/4/200416/6/2026
blocker.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection protection and execute limited SQL commands via URL-encoded "'" characters ("%27").
ModificadaMedia (5)1.6%—Protector System23/4/200416/6/2026
blocker_query.php in Protector System 1.15b1 for PHP-Nuke allows remote attackers to gain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.
ModificadaAlta (7.5)73%💥 ExploitISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+715/4/200416/6/2026
Múltiples desbordamientos de búfer basado en la pila en las rutinas de análisis de ICQ en el componente ISS Protocol Analysis Module (PAM), utilizado en varios productos RealSecure, Proventia y BlackICE, permite a atacantes remotos ejecutar código arbitrario mediante un respuesta SRV_MULTI conteniendo un paquete de…
ModificadaAlta (7.5)8.0%—ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+715/3/200416/6/2026
Desbordamiento de búfer basado en la pila en el Módulo de análisis de Protocolos (PAM) de ISS, usado en ciertas versiones de RealSecure Network 7.0 y Server Sensor 7.0, Proventia series A, G, y M, Desktop 7.0 y 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, y BlackICE Server Protection…
ModificadaBaja (2.1)0.33%—Pedestal Software Integrity Protection Driver31/12/200316/6/2026
NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command.
ModificadaAlta (7.5)6.0%💥 ExploitIisprotect31/12/200316/6/2026
iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.
ModificadaCrítica (9.8)1.6%—Pedestalsoftware Integrity Protection Driver31/12/200316/6/2026
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst…
ModificadaMedia (4.3)1.4%—IBM Internet Security Systems Blackice DefenderISS Blackice Server Protection31/12/200316/6/2026
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
ModificadaAlta (7.5)2.5%💥 ExploitIisprotect16/6/200316/6/2026
Vulnerabilidad de inyección SQL en la interfaz de administración web de iisPROTECT 2.2-r4 (y posiblemente versiones anteriores), permite que atacantes remotos ejecuten SQL arbitrario mediante ciertas variables, como se ha demostrado usando la variable GroupName en SiteAdmin.ASP.
ModificadaBaja (2.1)0.43%—Pedestal Software Integrity Protection Driver31/12/200216/6/2026
restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.
ModificadaMedia (5)2.7%💥 ExploitJohn Drake Killer Protection31/12/200216/6/2026
Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php.
ModificadaBaja (2.1)0.35%—Pedestal Software Integrity Protection Driver31/12/200216/6/2026
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.
ModificadaAlta (7.5)1.7%—Intel High-bandwidth Digital Content Protection20/11/200116/6/2026
Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.
ModificadaMedia (4.6)0.35%—Omnisecure Httprotect19/7/200116/6/2026
OmniSecure HTTProtect 1.1.1 allows a superuser without omnish privileges to modify a protected file by creating a symbolic link to that file.
Orbitaley — Vulnerabilidades