Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3206▲ 632 respecto a la semana anterior
Críticas / altas1515▲ 119 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2084 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 20% | 💥 Exploit | Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager | 23/12/2002 | 16/6/2026 | El comando COM_CHANGE_USER en MySQL 3.x anterirores de 3.23.54 y 4.x anteriores a 4.0.5 permite a atacantes remotos ganar privilegios mediante un ataque de fuerza bruta usando una contraseña de un carácter, lo que hace que MySQL compare la contraseña suministrada sólo con el primer carácter de la contraseña real. | |
| Modificada | Alta (7.5) | 9.5% | — | Oracle Application ServerOracle Reports | 4/10/2002 | 16/6/2026 | Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter. | |
| Modificada | Media (5) | 5.4% | 💥 Exploit | Oracle Application ServerOracle Reports | 4/10/2002 | 16/6/2026 | rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Webtrends Reporting Center | 18/6/2002 | 16/6/2026 | Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory. | |
| Modificada | Media (5) | 1.5% | — | Webtrends Reporting Center | 18/6/2002 | 16/6/2026 | WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Webtrends Enterprise Reporting ServerWebtrends Enterprise Reporting Server NT | 20/9/2001 | 16/6/2026 | WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20). | |
| Modificada | Alta (10) | 4.0% | — | Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+11 | 12/3/2001 | 16/6/2026 | Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. | |
| Modificada | Alta (7.5) | 4.0% | — | Businessobjects Crystal Reports | 10/1/2001 | 16/6/2026 | Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | IBM System Data Repository | 31/12/1999 | 16/6/2026 | sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication. |