Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 78% | 💥 Exploit | Flexense DupscoutFlexense DisksavvyFlexense SyncbreezeFlexense Diskpulse | 24/1/2018 | 17/6/2026 | A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the… | |
| Modificada | Media (6.9) | 0.40% | — | Siemens StarterSiemens Simatic ProsaveSiemens Simotion ScoutSiemens Simatic CFC+1 | 7/3/2015 | 17/6/2026 | Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a… | |
| Modificada | Media (5.4) | 0.27% | — | Scoutmob Local Deals & Event | 9/9/2014 | 17/6/2026 | The Scoutmob local deals & events (aka com.scoutmob.ile) application 3.0.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.7% | — | Forescout Counteract | 5/12/2012 | 16/6/2026 | The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to conduct ARP poisoning attacks via crafted packets. | |
| Modificada | Media (4.3) | 0.93% | — | Forescout Counteract | 5/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the a parameter to assets/login or (2) the query parameter to assets/rangesearch. | |
| Modificada | Media (5.8) | 8.9% | 💥 Exploit | Forescout Counteract | 5/12/2012 | 16/6/2026 | Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter. | |
| Modificada | Media (4.3) | 0.99% | — | Forescout Counteract | 11/6/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a forgotpass action or (2) the username parameter. | |
| Modificada | Media (4) | 0.33% | — | IBM Invscout.rte | 4/1/2012 | 16/6/2026 | The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Cmscout | 23/11/2011 | 16/6/2026 | SQL injection vulnerability in index.php in CMScout 2.0.8 allows remote attackers to execute arbitrary SQL commands via the album parameter in a photos action. | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | Cmscout | 3/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6) | 2.1% | 💥 Exploit | Cmscout | 17/4/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bit parameter to (1) admin.php and (2) index.php, different vectors than CVE-2008-3415. | |
| Modificada | Media (6) | 0.95% | 💥 Exploit | Cmscout | 17/4/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Netscout Ngenius InfinistreamNetscout Visualizer | 10/4/2009 | 16/6/2026 | NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en_US/domains/add_domain.jsp, which allows remote attackers to gain administrator privileges via a direct request. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Cmscout | 31/7/2008 | 16/6/2026 | Directory traversal vulnerability in common.php in CMScout 2.05, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bit parameter, as demonstrated by an upload to avatar/ of a .jpg file containing PHP sequences. | |
| Modificada | Baja (3.5) | 0.84% | — | Drupal Trailscout Module | 25/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote authenticated users, with create post permissions, to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Drupal Trailscout Module | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to improper use of the Drupal database API. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Cmscout | 17/7/2007 | 16/6/2026 | SQL injection vulnerability in forums.php in CMScout 1.23 and earlier allows remote attackers to execute arbitrary SQL commands via the f parameter in a forums action to index.php. | |
| Modificada | Media (5) | 1.8% | — | IBM Inventory Scout | 27/9/2006 | 16/6/2026 | Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Internet Scout Project Scout Portal Toolkit | 29/6/2006 | 16/6/2026 | SQL injection vulnerability in SPT--ForumTopics.php in Scout Portal Toolkit (SPT) 1.4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | |
| Modificada | Media (6.8) | 2.6% | — | Cmscout | 4/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CMScout 1.10 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Body field of a private message (PM), (2) BBCode, or (3) a forum post. | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Internet Scout Scout Portal Toolkit | 13/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the ss parameter in SPT--QuickSearch.php; (2) ParentId parameter in SPT--BrowseResources.php; (3) the ResourceId parameter in SPT--FullRecord.php;… | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Internet Scout Scout Portal ToolkitInternet Scout Project Scout Portal Toolkit | 13/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the ParentId parameter in SPT--BrowseResources.php, (2) ResourceId parameter in SPT--FullRecord.php, (3) ResourceOffset parameter in SPT--Home.php, and (4) F_UserName… | |
| Modificada | Media (5) | 2.6% | — | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form. | |
| Modificada | Media (5) | 2.6% | — | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it. |