Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.47% | — | Tibco HawkTibco Hawk Monitoring AgentTibco Runtime Agent | 5/6/2006 | 16/6/2026 | Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma. | |
| Modificada | Media (4.3) | 1.8% | — | Astalavista IT Engineering Contrexx | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF). | |
| Modificada | Alta (7.5) | 3.6% | — | Lexmark Printer Sharing | 8/2/2006 | 16/6/2026 | Vulnerabilidad no especificada en el servicio de Impresora Compartida de Lexmark LexBce Server (LexPPS) permite a atacantes remotos ejecutar código de su elección mediante vectores no especificados. NOTA: Esta información está basada en vagas revelaciones iniciales; se actualizarán los detalles después de que finalice… | |
| Modificada | Media (4.6) | 0.46% | — | Stefan Frings SMS Server Tools | 9/1/2006 | 16/6/2026 | Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Greywyvern Orca Ringmaker | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in ringmaker.php in Orca Ringmaker 2.3c and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Faqsystems Faqring Knowledge Base Software | 29/11/2005 | 16/6/2026 | SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Ringtail Casebook | 3/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.asp in Ringtail CaseBook 6.1.0 allows remote attackers to inject arbitrary web script or HTML via the users parameter. | |
| Modificada | Media (5) | 1.4% | — | Ringtail Casebook | 3/11/2005 | 16/6/2026 | login.asp in Ringtail CaseBook 6.1.0 displays different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames. | |
| Modificada | Media (5) | 0.88% | — | Ciscoworks Management Center FOR IDS SensorsCiscoworks Monitoring Center FOR Security | 26/8/2005 | 16/6/2026 | Unspecified vulnerability in the SSL certificate checking functionality in Cisco CiscoWorks Management Center for IDS Sensors (IDSMC) 2.0 and 2.1, and Monitoring Center for Security (Security Monitor or Secmon) 1.1 through 2.0 and 2.1, allows remote attackers to spoof a Cisco Intrusion Detection Sensor (IDS) or… | |
| Modificada | Media (5) | 1.8% | — | Astalavista IT Engineering Contrexx | 3/8/2005 | 16/6/2026 | Contrexx anterior a la 1.0.5 permite que atacantes remotos obtengan información confidencial mediante una petición directa a /config/version.xml. | |
| Modificada | Alta (7.5) | 1.6% | — | Astalavista IT Engineering Contrexx | 3/8/2005 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en Contrexx anterior a la 1.0.5 permite que atacantes remotos ejecuten comandos SQL arbitrarios mediante el parámetro "value" al módulo poll o el parámetro "pld" al módulo gallery | |
| Modificada | Media (4.3) | 1.8% | — | Astalavista IT Engineering Contrexx | 3/8/2005 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados en Contrexx anterior a la 1.0.5 permite que atacantes remotos inyecten script web o HTML mediante el parámetro "term" al módulo de búsqueda o el título en el módulo de agregación de blog. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (5) | 1.7% | — | Serverscheck Monitoring Software | 29/5/2005 | 16/6/2026 | Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Michael Kohn Ringtonetools | 10/1/2005 | 16/6/2026 | Desbordamiento de búfer en la función parse_emelody en parse_emelody.c de ringtonetools 2.22 permite a atacantes ejecutar código de su elección mediante un fichero eMelody artesanal. | |
| Modificada | Alta (7.5) | 1.6% | — | Roaring Penguin MimedefangMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerSuse Linux | 10/1/2005 | 16/6/2026 | MIMEDefang de MIME-tools 5.414 permite a atacantes remotos sortear escaner de virus mediante adjuntos en correo electrónico con virus que contengan una cadena de límite vacia en la cabecera Content-Type. | |
| Modificada | Baja (2.1) | 0.36% | — | Roaring Penguin PppoeDebian Linux | 23/12/2004 | 16/6/2026 | Roaring Penguin pppoe, cuando se ejecuta con setuid root, no libera privilegios adecuadamente, lo que permite a usuarios locales sobreescribir ficheros arbitrarios. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Vivisimo Clustering Engine | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program. | |
| Modificada | Alta (7.5) | 1.9% | — | Gert Doering Mgetty | 18/8/2003 | 16/6/2026 | cnd.c en mgetty 1.1.28 y anteriores no filtra apropiadamante caractéres no imprimibles y comillas, lo que puede permitir a atacantes remotos ejecutar comandos arbitrarios mediante metacaractéres de shell en las cadenas (1) ID de llamante o (2) nombre de llamante. | |
| Modificada | Alta (7.5) | 3.7% | — | Gert Doering Mgetty | 17/1/2003 | 16/6/2026 | Desbordamiento de búfer en cnd-program de mgetty anteriores a 1.1.29 permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante cadena de ID de llamante con con un argumento CallerName largo. | |
| Modificada | Baja (2.1) | 0.36% | — | Gert Doering Mgetty | 17/1/2003 | 16/6/2026 | faxspool en mgetty anteriores a 1.1.29 usa un directorio de bobinado (spool) escribible por todo el mundo para los faxes salientes, lo que permite a usuarios locales modificar los privilegios de transmisíón de fax. | |
| Modificada | Alta (7.2) | 0.41% | — | Gringotts | 31/12/2002 | 16/6/2026 | Multiple buffer overflows in Gringotts 0.5.9 allows local users to execute arbitrary commands via unknown attack vectors. | |
| Modificada | Media (5) | 1.3% | — | Sonicwall Content Filtering | 31/12/2002 | 16/6/2026 | SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name. | |
| Modificada | Alta (10) | 3.0% | — | Springer Verlag Berlin Heidelberg Simple Wais | 31/12/2002 | 16/6/2026 | Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Macromedia Sitespring | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter. |