Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.77% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Enterprise Edition before 8.5 FP6 allows remote attackers to execute arbitrary code via a long password. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue. | |
| Modificada | Media (6.8) | 1.2% | — | IBM Omnifind | 12/11/2010 | 16/6/2026 | Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by replaying a session ID (aka SID) value. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | IBM Omnifind | 12/11/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a saveNewUser action. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Omnifind | 12/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to inject arbitrary web script or HTML via the command parameter to the administration interface, as demonstrated by the command parameter to ESAdmin/collection.do. | |
| Modificada | Media (5.4) | 1.9% | — | Alcatel-lucent Omnivista 4760 Server | 23/9/2010 | 16/6/2026 | Stack-based buffer overflow in the HTTP proxy service in Alcatel-Lucent OmniVista 4760 server before R5.1.06.03.c_Patch3 allows remote attackers to execute arbitrary code or cause a denial of service (service crash) via a long request. | |
| Modificada | Media (6.9) | 0.96% | — | Alcatel-lucent CcagentAlcatel-lucent Omnitouch Contact Center | 23/9/2010 | 16/6/2026 | The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote… | |
| Modificada | Alta (7.6) | 1.1% | — | Alcatel-lucent CcagentAlcatel-lucent Omnitouch Contact Center | 23/9/2010 | 16/6/2026 | The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables maintenance access, which allows remote attackers to monitor or reconfigure Contact Center operations via vectors involving TSA_maintenance.exe. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Omnistaretools Omnistar Recruiting | 25/8/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to inject arbitrary web script or HTML via the job2 parameter. | |
| Modificada | Media (5) | 1.3% | — | Omnigroup Omniweb | 24/3/2010 | 16/6/2026 | Integer overflow in OmniWeb allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Newgensoft Omnidocs | 23/2/2010 | 16/6/2026 | SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6) | 2.7% | 💥 Exploit | Omnisoftsol Vidsharepro | 22/5/2009 | 16/6/2026 | Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Omnisoftsol Vidsharepro | 20/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Omnisoftsol Vidsharepro | 20/5/2009 | 16/6/2026 | SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Alta (7.8) | 2.6% | 💥 Exploit | Ocp2 Omnicom Content Platform | 28/1/2009 | 16/6/2026 | Absolute path traversal vulnerability in admin/fileKontrola/browser.asp in Omnicom Content Platform (OCP) 2.0 allows remote attackers to list arbitrary directories via a full pathname in the root parameter. | |
| Modificada | Alta (10) | 8.8% | 💥 Exploit | Alcatel-lucent Omnipcx Office | 2/4/2008 | 16/6/2026 | cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter. | |
| Modificada | Alta (8.5) | 2.4% | — | Alcatel-lucent Omnipcx | 20/11/2007 | 16/6/2026 | The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Omnistar Interactive Omnistar Live | 30/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Omnistar Live allow remote attackers to inject arbitrary web script or HTML via (1) the category_id parameter to users/kb.php, and possibly (3) the Email Box field in profile.php. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Alcatel-lucent Omnivista | 22/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the action parameter to php-bin/Webclient.php or (2) the Langue parameter to the default URI. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Al-enterprise Omnipcx Enterprise Communication Server | 18/9/2007 | 16/6/2026 | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Omnistar Interactive Omnistar Article Manager | 18/9/2007 | 16/6/2026 | SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Omnistar Lib2 PHP Library | 14/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in adm/my_statistics.php in Omnistar Lib2 PHP 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Alcatel-lucent Omnipcx | 7/6/2007 | 16/6/2026 | Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems. | |
| Modificada | Media (6.9) | 0.64% | 💥 Exploit | Omnikey.aaitg Omnikey Cardman 4040 | 10/3/2007 | 16/6/2026 | Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges. |