Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.2% | 💥 Exploit | Innovaphone PBX | 25/8/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authentication of administrators for requests that modify configurations or user accounts, as demonstrated by (1) changing the administrator password via a crafted request to… | |
| Modificada | Media (4.3) | 2.0% | — | Openstack Nova | 7/8/2014 | 17/6/2026 | api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance… | |
| Modificada | Media (4) | 2.0% | — | Openstack Nova | 6/3/2014 | 17/6/2026 | The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which triggers the creation of a new ephemeral disk backing file. | |
| Modificada | Baja (3.3) | 0.48% | — | Openstack Nova | 23/1/2014 | 17/6/2026 | OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots. | |
| Modificada | Media (4.7) | 0.30% | — | Novatech Orion5 DNP MasterNovatech Orion5 DNP SlaveNovatech Orion5r DNP MasterNovatech Orion5r DNP Slave+2 | 21/12/2013 | 16/6/2026 | NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically proximate attackers to cause a denial of service (driver crash and process restart) via crafted input over a serial line. | |
| Modificada | Alta (7.1) | 1.3% | — | Novatech Orion5 DNP MasterNovatech Orion5 DNP SlaveNovatech Orion5r DNP MasterNovatech Orion5r DNP Slave+2 | 21/12/2013 | 16/6/2026 | NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attackers to cause a denial of service (driver crash and process restart) via a crafted DNP3 TCP packet. | |
| Modificada | Media (6) | 1.8% | — | Openstack Nova | 16/9/2013 | 16/6/2026 | OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor… | |
| Modificada | Media (5) | 4.8% | — | Openstack Cinder FolsomOpenstack Compute (nova) EssexOpenstack Compute (nova) FolsomOpenstack Folsom+2 | 3/4/2013 | 16/6/2026 | The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion… | |
| Modificada | Media (5.8) | 1.2% | — | Earl Dunovant Monthly Archive BY Node Type | 31/10/2012 | 16/6/2026 | The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attackers to access restricted nodes via unspecified vectors. | |
| Modificada | Alta (9.3) | 4.3% | — | Caminova Djvu Browser Plug-in | 19/9/2012 | 16/6/2026 | Heap-based buffer overflow in npdjvu.dll in Caminova DjVu Browser Plug-in 6.1.4 Build 27351 and other versions before 6.1.4.27993 allows remote attackers to execute arbitrary code via a crafted Sjbz chunk in a djvu file. | |
| Modificada | Media (6.9) | 0.36% | — | Novadevelopement Photoimpact X3 | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in PhotoImpact X3 13.00.0000.0 allows local users to gain privileges via a Trojan horse bwsconst.dll file in the current working directory, as demonstrated by a directory that contains a .ufp or .ufo file. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Media (4.9) | 1.9% | — | Openstack FolsomOpenstack Nova | 20/8/2012 | 16/6/2026 | virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for… | |
| Modificada | Media (4) | 2.1% | — | Openstack Nova | 17/8/2012 | 16/6/2026 | OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name. | |
| Modificada | Baja (3.5) | 1.5% | — | Openstack Nova | 7/6/2012 | 16/6/2026 | Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Nova-cms Nova CMS | 18/2/2012 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType parameter to optimizer/index.php, (2) id parameter to administrator/modules/moduleslist.php, (3) filename parameter to includes/function/gets.php, or (4) conf[blockfile]… | |
| Modificada | Media (4.9) | 1.7% | — | Openstack EssexOpenstack Nova | 13/1/2012 | 16/6/2026 | Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter. | |
| Modificada | Media (6) | 1.8% | — | Openstack Nova | 23/12/2011 | 16/6/2026 | Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest. | |
| Modificada | Media (5) | 1.4% | — | Earl Dunovant Week | 27/2/2010 | 16/6/2026 | The week_post_page function in the Weekly Archive by Node Type module 6.x before 6.x-2.7 for Drupal does not properly implement node access restrictions when constructing SQL queries, which allows remote attackers to read restricted node listings via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Novaboard | 11/2/2010 | 16/6/2026 | SQL injection vulnerability in header.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the nova_name cookie parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Novaboard | 11/2/2010 | 16/6/2026 | SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter in a search action. | |
| Modificada | Media (5) | 1.4% | — | Innovationdp Fdr/upstrean | 19/10/2009 | 16/6/2026 | INNOVATION Data Processing FDR/UPSTREAM 3.3.0 (GA Oct 2003) allows remote attackers to cause a denial of service (service outage) via a sequence of TCP SYN packets to many ports, as demonstrated using nmap. NOTE: the vendor's testing reportedly found that no denial of service occurred. | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Novastor Novanet | 9/3/2009 | 16/6/2026 | Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute arbitrary code on Linux platforms via a long username field during backup domain authentication, related to libnnlindtb.so; or (2) cause a denial of service (daemon crash) on Windows platforms via a… | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Xnova | 2/2/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1, allows remote attackers to execute arbitrary PHP code via a URL in the xnova_root_path parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Xnova | 2/2/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in an older version of Xnova, possibly 0.8 sp1, allows remote attackers to execute arbitrary PHP code via a URL in the ugamela_root_path parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Innovaage Innovashop | 16/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge InnovaShop allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to msg.jsp, and the (2) contentid parameter to tc/contents/home001.jsp. |