Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 19% | — | Alienvault Open Source Security Information Management | 9/10/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3)… | |
| Modificada | Alta (7.5) | 1.4% | — | Alienvault Open Source Security Information Management | 20/8/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to… | |
| Modificada | Media (4.3) | 1.8% | — | Alienvault Open Source Security Information Management | 15/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to… | |
| Modificada | Media (5) | 2.1% | — | Asterisk Open SourceCertified AsteriskAsterisk Digiumphones | 1/4/2013 | 16/6/2026 | main/http.c in the HTTP server in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 before 1.8.15-cert2; and Asterisk Digiumphones 10.x-digiumphones before 10.12.2-digiumphones does not properly restrict Content-Length values, which allows remote… | |
| Modificada | Alta (7.5) | 2.6% | — | Asterisk Open Source | 1/4/2013 | 16/6/2026 | Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbitrary code via a long sprop-parameter-sets H.264 media attribute in a SIP Session Description Protocol (SDP) header. | |
| Modificada | Media (5) | 1.3% | — | Asterisk Open SourceCertified AsteriskAsterisk Business EditionAsterisk Digiumphones | 1/4/2013 | 16/6/2026 | The SIP channel driver in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 before 1.8.15-cert2; Asterisk Business Edition (BE) C.3.x before C.3.8.1; and Asterisk Digiumphones 10.x-digiumphones before 10.12.2-digiumphones exhibits different behavior for… | |
| Modificada | Media (4.3) | 1.8% | — | JAM Warehouse Knowledgetree Open Source | 20/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) login.php, (2) admin.php, or (3) preferences.php. | |
| Modificada | Alta (9) | 3.6% | — | Asterisk Open SourceSangoma AsteriskCertified AsteriskAsterisk Digiumphones+1 | 31/8/2012 | 16/6/2026 | Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 allows remote authenticated… | |
| Modificada | Media (4.3) | 2.2% | — | Alienvault Open Source Security Information Management | 3/7/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an… | |
| Modificada | Media (6.5) | 1.4% | — | Alienvault Open Source Security Information Management | 3/7/2012 | 16/6/2026 | SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter. | |
| Modificada | Media (4) | 2.1% | — | Certified AsteriskAsterisk Open SourceSangoma Asterisk | 2/6/2012 | 16/6/2026 | chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by closing a connection in… | |
| Modificada | Media (6.5) | 2.2% | — | Asterisk Open Source | 30/4/2012 | 16/6/2026 | chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.11.1 and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4, when the trustrpid option is enabled, allows remote authenticated users to cause a denial of service (daemon crash) by sending a SIP UPDATE message that triggers… | |
| Modificada | Media (6.5) | 2.7% | — | Asterisk Open Source | 30/4/2012 | 16/6/2026 | Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 allows remote authenticated users to cause a denial of service or possibly have unspecified other impact via a series of KEYPAD_BUTTON_MESSAGE events. | |
| Modificada | Media (6.5) | 2.7% | — | Asterisk Open Source | 30/4/2012 | 16/6/2026 | main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirements, which allows remote authenticated users to execute arbitrary… | |
| Modificada | Media (4) | 1.8% | — | Movabletype Movable Type Open SourceMovabletype Movable Type EnterpriseMovabletype Movable Type AdvancedMovabletype Movable Type PRO | 3/3/2012 | 16/6/2026 | The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files by leveraging the template-designer role. | |
| Modificada | Media (4.3) | 1.9% | — | Movabletype Movable Type Open SourceMovabletype Movable Type EnterpriseMovabletype Movable Type AdvancedMovabletype Movable Type PRO | 3/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the dbuser parameter, a different vulnerability than CVE-2012-0318. | |
| Modificada | Media (6.5) | 2.4% | — | Movabletype Movable Type Open SourceMovabletype Movable Type EnterpriseMovabletype Movable Type AdvancedMovabletype Movable Type PRO | 3/3/2012 | 16/6/2026 | The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary commands by leveraging the file-upload feature, related to an "OS Command Injection" issue. | |
| Modificada | Media (4.3) | 1.3% | — | Movabletype Movable Type Open SourceMovabletype Movable Type EnterpriseMovabletype Movable Type AdvancedMovabletype Movable Type PRO | 3/3/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262. | |
| Modificada | Media (4.3) | 2.4% | — | Asterisk Open Source | 25/1/2012 | 16/6/2026 | chan_sip.c in Asterisk Open Source 1.8.x before 1.8.8.2 and 10.x before 10.0.1, when the res_srtp module is used and media support is improperly configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SDP message with a crypto attribute and a (1) video… | |
| Modificada | Media (6.8) | 2.4% | — | Asterisk Open Source | 21/10/2011 | 16/6/2026 | chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables during request parsing, which allows remote authenticated users to cause a denial of service (daemon crash) via a malformed request. | |
| Modificada | Alta (7.5) | 0.97% | — | Alienvault Open Source Security Information Management | 21/12/2009 | 16/6/2026 | SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary SQL commands via the id_document parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Alienvault Open Source Security Information Management | 21/12/2009 | 16/6/2026 | Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | Alienvault Open Source Security Information Management | 21/12/2009 | 16/6/2026 | Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a… | |
| Modificada | Alta (7.5) | 4.8% | — | Alienvault Open Source Security Information Management | 21/12/2009 | 16/6/2026 | AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the uniqueid parameter to (1) wcl.php, (2) storage_graphs.php, (3) storage_graphs2.php, (4) storage_graphs3.php, and (5)… | |
| Modificada | Alta (7.8) | 2.6% | — | AsteriskAsterisk Open SourceAsterisk OpensourceSangoma Asterisk+1 | 8/9/2009 | 16/6/2026 | The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of… |