Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

230 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.5)1.4%💥 ExploitAdvantech Webaccess22/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6)0.47%—Advantech Webaccess21/2/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.
ModificadaMedia (6.5)1.1%—Advantech Webaccess21/2/201216/6/2026
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
ModificadaAlta (7.5)1.1%—Advantech Webaccess21/2/201216/6/2026
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by leveraging the ability to write arbitrary content to any pathname.
ModificadaAlta (10)6.9%💥 ExploitAdvantech Webaccess21/2/201216/6/2026
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.
ModificadaMedia (5)4.5%💥 ExploitAdvantech Webaccess21/2/201216/6/2026
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (5)1.1%—Advantech Webaccess21/2/201216/6/2026
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (6.4)1.2%—Advantech Webaccess21/2/201216/6/2026
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.
ModificadaMedia (5)1.2%—Advantech Webaccess21/2/201216/6/2026
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
ModificadaMedia (6)0.47%—Advantech Webaccess21/2/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaAlta (7.5)1.1%—Advantech Webaccess21/2/201216/6/2026
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.
ModificadaMedia (4.3)0.91%—Advantech Webaccess21/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote attackers to execute arbitrary code via a long string value in unspecified parameters.
ModificadaAlta (10)2.0%—Advantech Webaccess21/2/201216/6/2026
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified parameters.
ModificadaMedia (4.3)0.91%—Advantech Webaccess21/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
ModificadaMedia (4.3)0.91%—Advantech Webaccess21/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
ModificadaAlta (7.5)1.1%—Advantech Webaccess21/2/201216/6/2026
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string input.
ModificadaAlta (10)18%💥 ExploitBroadwin Webaccess6/2/201216/6/2026
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.
ModificadaMedia (4.3)0.95%—Novell Groupwise Webaccess28/8/200716/6/2026
Cross-site scripting (XSS) vulnerability in the webacc servlet in Novell GroupWise 6.5 WebAccess allows remote attackers to inject arbitrary web script or HTML via the User.Id parameter, as demonstrated by a URL within a url field in a STYLE element, possibly due to an incomplete fix for CVE-2004-2103.2.
ModificadaMedia (4.3)1.9%💥 ExploitNovell GroupwiseNovell Groupwise Webaccess31/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
ModificadaMedia (4.3)2.0%—Novell Groupwise Webaccess11/8/200616/6/2026
Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence.
Orbitaley — Vulnerabilidades