Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 1.2% | — | Pulsecms Pulse CMS | 26/3/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary PHP code via vectors related to improper handling of login failures by includes/login.php; and allow remote authenticated users to write to arbitrary files and execute arbitrary… | |
| Modificada | Media (4.3) | 1.1% | — | Pulsecms Pulse CMS | 23/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter. | |
| Modificada | Media (6.9) | 0.34% | — | Pulseaudio | 18/3/2010 | 16/6/2026 | The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Indianpulses COM Gameserver | 28/1/2010 | 16/6/2026 | SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a gameserver action to index.php. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Indianpulses COM Gameserver | 3/9/2009 | 16/6/2026 | SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php. | |
| Modificada | Alta (7.2) | 0.74% | 💥 Exploit | Pulseaudio | 17/7/2009 | 16/6/2026 | Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink. | |
| Modificada | Alta (7.2) | 0.56% | — | Pulseaudio | 29/1/2008 | 16/6/2026 | The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource… | |
| Modificada | Alta (7.8) | 7.4% | 💥 Exploit | Pulseaudio | 2/4/2007 | 16/6/2026 | PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a… | |
| Modificada | Alta (7.5) | 1.2% | — | Horsburgh Npulse | 19/7/2001 | 16/6/2026 | Vulnerability in the server for nPULSE before 0.53p4. | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Infopulse Gatekeeper | 13/7/2000 | 16/6/2026 | Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string. |