Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1895 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.3%—Cisco Voip Phone Cp-7940Cisco Skinny Client Control Protocol Software4/10/200216/6/2026
Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2."
ModificadaMedia (5)1.3%—Cisco VPN Client5/9/200216/6/2026
Desbordamiento de búfer en Cliente de Red Privada Virtual (VPN) de Cisco 3.5.4 y anteriores permite a atacantes remotos causar una denegación de servicio mediante un Intecambio de Clave de Intenet (Internet Key Exchange - IKE) con un contenido útil (payload) de una Índice de Parámetro de Seguridad (Security Parameter…
ModificadaMedia (5)2.2%—Cisco VPN Client5/9/200216/6/2026
El Cliente de Red Privada Virtual (VPN) de Cisco 3.5.4 y anteriores permite a atacantes remotos causar una denegación de servicio (consumición de CPU) mediante un paquete con una carga útil de longitud cero.
ModificadaAlta (7.2)1.5%💥 ExploitCisco VPN Client28/5/200216/6/2026
Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.
ModificadaMedia (5)5.4%—FreeradiusGNU RadiusIcradiusLivingston Radius+74/3/200216/6/2026
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
ModificadaAlta (7.5)8.5%—Ascend RadiusFreeradiusGNU RadiusIcradius+84/3/200216/6/2026
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data.
ModificadaAlta (7.5)2.2%—Citrix ICA Client13/12/200116/6/2026
El cliente Citrix Independent Computing Architecture (ICA) para Windows 6.1 permite a sitios web remotos con intenciones maliciosas, la ejecución de código arbitrario mediante un fichero .ICA, que es descargado y automáticamente ejecutado por el cliente.
ModificadaMedia (5)1.2%—Gnutella Client31/8/200116/6/2026
Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags.
ModificadaAlta (10)3.1%—Lotus Domino R5 ClientLotus Domino R5 Server12/3/200116/6/2026
Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier.
ModificadaAlta (10)2.0%—Novell ClientSymantec Norton Antivirus20/10/200016/6/2026
Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system.
ModificadaMedia (5)3.3%💥 ExploitAlt-n Worldclient12/7/200016/6/2026
The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
ModificadaAlta (10)6.7%—ISC Dhcp Client24/6/200016/6/2026
ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters.
ModificadaBaja (2.1)0.77%—Napster Client26/3/200016/6/2026
Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.
ModificadaAlta (7.5)3.2%—ISC Dhcp Client31/12/199916/6/2026
Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.
ModificadaMedia (4.6)0.33%—Prosoft Engineering Netware Client14/11/199916/6/2026
ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session.
ModificadaAlta (7.5)2.7%—Mutt Mail Client27/9/199916/6/2026
Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.
ModificadaMedia (5)1.6%—Kvirc IRC Client24/9/199916/6/2026
Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick <soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.
ModificadaMedia (4.6)0.35%—Gftp FTP Client5/9/199916/6/2026
El cliente de FTP gFTP versión 1.13, y otras versiones anteriores a 2.0.0 almacenan contraseñas en texto plano en (1) la ventana de registro(log) o (2) en un fichero de registro.
ModificadaMedia (4.6)0.32%—Backweb Technologies Backweb Client24/12/199816/6/2026
BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.
ModificadaMedia (5.1)1.2%—Palace Client2/10/199816/6/2026
A malicious Palace server can force a client to execute arbitrary programs.