Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

2111 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.47%—Tibco HawkTibco Hawk Monitoring AgentTibco Runtime Agent5/6/200616/6/2026
Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma.
ModificadaMedia (4.3)1.8%—Astalavista IT Engineering Contrexx19/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).
ModificadaAlta (7.5)3.6%—Lexmark Printer Sharing8/2/200616/6/2026
Vulnerabilidad no especificada en el servicio de Impresora Compartida de Lexmark LexBce Server (LexPPS) permite a atacantes remotos ejecutar código de su elección mediante vectores no especificados. NOTA: Esta información está basada en vagas revelaciones iniciales; se actualizarán los detalles después de que finalice…
ModificadaMedia (4.6)0.46%—Stefan Frings SMS Server Tools9/1/200616/6/2026
Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors.
ModificadaAlta (7.5)1.4%💥 ExploitGreywyvern Orca Ringmaker1/12/200516/6/2026
SQL injection vulnerability in ringmaker.php in Orca Ringmaker 2.3c and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter.
ModificadaAlta (7.5)1.1%💥 ExploitFaqsystems Faqring Knowledge Base Software29/11/200516/6/2026
SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.2%—Ringtail Casebook3/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in login.asp in Ringtail CaseBook 6.1.0 allows remote attackers to inject arbitrary web script or HTML via the users parameter.
ModificadaMedia (5)1.4%—Ringtail Casebook3/11/200516/6/2026
login.asp in Ringtail CaseBook 6.1.0 displays different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
ModificadaMedia (5)0.88%—Ciscoworks Management Center FOR IDS SensorsCiscoworks Monitoring Center FOR Security26/8/200516/6/2026
Unspecified vulnerability in the SSL certificate checking functionality in Cisco CiscoWorks Management Center for IDS Sensors (IDSMC) 2.0 and 2.1, and Monitoring Center for Security (Security Monitor or Secmon) 1.1 through 2.0 and 2.1, allows remote attackers to spoof a Cisco Intrusion Detection Sensor (IDS) or…
ModificadaMedia (5)1.8%—Astalavista IT Engineering Contrexx3/8/200516/6/2026
Contrexx anterior a la 1.0.5 permite que atacantes remotos obtengan información confidencial mediante una petición directa a /config/version.xml.
ModificadaAlta (7.5)1.6%—Astalavista IT Engineering Contrexx3/8/200516/6/2026
Múltiples vulnerabilidades de inyección de SQL en Contrexx anterior a la 1.0.5 permite que atacantes remotos ejecuten comandos SQL arbitrarios mediante el parámetro "value" al módulo poll o el parámetro "pld" al módulo gallery
ModificadaMedia (4.3)1.8%—Astalavista IT Engineering Contrexx3/8/200516/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados en Contrexx anterior a la 1.0.5 permite que atacantes remotos inyecten script web o HTML mediante el parámetro "term" al módulo de búsqueda o el título en el módulo de agregación de blog.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaMedia (5)1.7%—Serverscheck Monitoring Software29/5/200516/6/2026
Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.
ModificadaAlta (10)16%💥 ExploitMichael Kohn Ringtonetools10/1/200516/6/2026
Desbordamiento de búfer en la función parse_emelody en parse_emelody.c de ringtonetools 2.22 permite a atacantes ejecutar código de su elección mediante un fichero eMelody artesanal.
ModificadaAlta (7.5)1.6%—Roaring Penguin MimedefangMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerSuse Linux10/1/200516/6/2026
MIMEDefang de MIME-tools 5.414 permite a atacantes remotos sortear escaner de virus mediante adjuntos en correo electrónico con virus que contengan una cadena de límite vacia en la cabecera Content-Type.
ModificadaBaja (2.1)0.36%—Roaring Penguin PppoeDebian Linux23/12/200416/6/2026
Roaring Penguin pppoe, cuando se ejecuta con setuid root, no libera privilegios adecuadamente, lo que permite a usuarios locales sobreescribir ficheros arbitrarios.
ModificadaMedia (4.3)1.4%💥 ExploitVivisimo Clustering Engine31/12/200316/6/2026
Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.
ModificadaAlta (7.5)1.9%—Gert Doering Mgetty18/8/200316/6/2026
cnd.c en mgetty 1.1.28 y anteriores no filtra apropiadamante caractéres no imprimibles y comillas, lo que puede permitir a atacantes remotos ejecutar comandos arbitrarios mediante metacaractéres de shell en las cadenas (1) ID de llamante o (2) nombre de llamante.
ModificadaAlta (7.5)3.7%—Gert Doering Mgetty17/1/200316/6/2026
Desbordamiento de búfer en cnd-program de mgetty anteriores a 1.1.29 permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante cadena de ID de llamante con con un argumento CallerName largo.
ModificadaBaja (2.1)0.36%—Gert Doering Mgetty17/1/200316/6/2026
faxspool en mgetty anteriores a 1.1.29 usa un directorio de bobinado (spool) escribible por todo el mundo para los faxes salientes, lo que permite a usuarios locales modificar los privilegios de transmisíón de fax.
ModificadaAlta (7.2)0.41%—Gringotts31/12/200216/6/2026
Multiple buffer overflows in Gringotts 0.5.9 allows local users to execute arbitrary commands via unknown attack vectors.
ModificadaMedia (5)1.3%—Sonicwall Content Filtering31/12/200216/6/2026
SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name.
ModificadaAlta (10)3.0%—Springer Verlag Berlin Heidelberg Simple Wais31/12/200216/6/2026
Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.
ModificadaAlta (7.5)2.8%💥 ExploitMacromedia Sitespring4/10/200216/6/2026
Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.