Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | IBM Websphere Extreme Scale | 16/10/2013 | 16/6/2026 | The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Websphere Extreme Scale | 16/10/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.2) | 0.29% | — | Checkpoint Zonealarm Extreme Security | 25/8/2012 | 16/6/2026 | Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler… | |
| Modificada | Media (5) | 1.4% | — | Rabidhamster R2/extreme | 21/2/2012 | 16/6/2026 | RabidHamster R2/Extreme 1.65 and earlier uses a small search space of values for the PIN number, which allows remote attackers to obtain the PIN number via a brute force attack. | |
| Modificada | Alta (8.5) | 3.8% | — | Rabidhamster R2/extreme | 21/2/2012 | 16/6/2026 | Stack-based buffer overflow in RabidHamster R2/Extreme 1.65 and earlier allows remote authenticated users to execute arbitrary code via a long string to TCP port 23. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Rabidhamster R2/Rabidhamster R2/extreme | 21/2/2012 | 16/6/2026 | Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the File command. | |
| Modificada | Alta (7.1) | 1.4% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 allows remote attackers to cause a denial of service (networking outage) via a crafted DHCP reply. | |
| Modificada | Baja (2.6) | 1.7% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary intranet TCP traffic by leveraging write… | |
| Modificada | Media (6.1) | 0.82% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote attackers to cause a denial of service (resource consumption and… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Extremejoomla COM J-projects | 13/4/2010 | 16/6/2026 | SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the project parameter in a projects action to index.php. | |
| Modificada | Media (5) | 1.2% | — | Apple Airport ExpressApple Airport ExtremeApple Time Capsule | 10/3/2010 | 16/6/2026 | The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command. | |
| Modificada | Media (4) | 2.2% | 💥 Exploit | Digital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+2 | 19/8/2009 | 16/6/2026 | The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the… | |
| Modificada | Media (4.3) | 1.0% | — | Evolution-extreme Nuke Evolution Xtreme | 28/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 0.63% | — | Falt4 Extreme | 19/2/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the manage_users handler in admin/index.php in Falt4 CMS (aka Falt4 Extreme) RC4 allow remote attackers to hijack the authentication of administrators for requests that change passwords via the (1) edit and (2) edit_now actions. | |
| Modificada | Media (4.3) | 1.5% | — | Apple Airport Extreme Base Station | 20/3/2008 | 16/6/2026 | Unspecified vulnerability in Apple AirPort Extreme Base Station Firmware 7.3.1 allows remote attackers to cause a denial of service (file sharing hang) via a crafted AFP request, related to "input validation." | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Extremez Print ServerExtremez-ip File Server | 13/2/2008 | 16/6/2026 | ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large integer in this field in a packet to the Service Location Protocol… | |
| Modificada | Media (5) | 1.8% | — | Group Logic Extremez-ip File ServerGroup Logic Extremez-ip Print Server | 13/2/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allow remote attackers to read arbitrary (1) gif, (2) png, (3) jpg, (4) xml, (5) ico, (6) zip, and (7) html files via a "..\" (dot dot backslash) sequence in the filename. | |
| Modificada | Media (5) | 1.7% | — | Group Logic Extremez-ip File ServerGroup Logic Extremez-ip Print Server | 13/2/2008 | 16/6/2026 | ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allows remote attackers to cause a denial of service (daemon crash) via an invalid UAM field in a request to the Apple Filing Protocol (AFP) service on TCP port 548. | |
| Modificada | Media (4.3) | 4.6% | 💥 Exploit | Falt4 CMS Falt4 Extreme RC4 | 11/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme RC4 10.9.2007 allow remote attackers to inject arbitrary web script or HTML via the handler parameter to (1) index.php and possibly (2) admin/index.php, and (3) the topic parameter to modules/feed/feed.php (aka modules/feed.php). | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Falt4 CMS Falt4 Extreme RC4 | 11/12/2007 | 16/6/2026 | SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows remote attackers to execute arbitrary SQL commands via the nav_ID parameter. | |
| Modificada | Baja (2.1) | 0.34% | — | Intel Core 2 DUO E4000Intel Core 2 DUO E6000Intel Core 2 Extreme X6800 | 3/7/2007 | 16/6/2026 | The Intel Core 2 Extreme processor X6800 and Core 2 Duo desktop processor E6000 and E4000 incorrectly set the memory page Access (A) bit for a page in certain circumstances involving proximity of the code segment limit to the end of a code page, which has unknown impact and attack vectors on certain operating systems… | |
| Modificada | Alta (7.5) | 1.5% | — | Extreme Phpbb | 24/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Final allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions.php or (2) functions_portal.php in includes/. | |
| Modificada | Alta (7.5) | 2.7% | — | Apple Airport Extreme | 8/3/2007 | 16/6/2026 | The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the "Block incoming IPv6 connections" setting, which might allow remote attackers to bypass intended access restrictions by establishing IPv6 sessions that would have been rejected over IPv4. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Extreme Phpbb | 26/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Extremepow Extreme File Hosting | 12/2/2007 | 16/6/2026 | Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as (1) .rar.php or (2) .zip.php. |