Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 295 respecto a la semana anterior
Críticas / altas1347▲ 81 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.4% | — | Novell Zenworks Patch Management Server | 30/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp. | |
| Modificada | Baja (2.1) | 0.34% | — | Rogers Software Source Mgdiff Patch Viewer | 27/10/2005 | 16/6/2026 | viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Media (4.3) | 1.4% | — | Dogpatch Software Cfwebstore | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Alta (7.5) | 2.1% | — | Dogpatch Software Cfwebstore | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters. | |
| Modificada | Alta (7.2) | 1.5% | — | Cluecentral Suexec.patch | 6/8/2004 | 16/6/2026 | The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different… | |
| Modificada | Alta (7.5) | 1.4% | — | SUN Patch Manager | 19/4/2004 | 16/6/2026 | The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname. | |
| Modificada | Media (4.6) | 1.0% | — | Grsecurity Kernel Patch | 31/12/2002 | 16/6/2026 | grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory. | |
| Modificada | Alta (10) | 1.2% | — | SUN Patchpro | 31/12/2002 | 16/6/2026 | Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files." | |
| Modificada | Alta (7.5) | 3.4% | — | Craig Patchett Fileseek | 18/6/2002 | 16/6/2026 | FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters. | |
| Modificada | Media (5) | 8.3% | — | Craig Patchett Fileseek | 18/6/2002 | 16/6/2026 | Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (2) foot parameters, which are not properly filtered. |