Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.52% | — | Vitec AvediaserverAI | 15/5/2024 | 17/6/2026 | Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalate privileges via a crafted script. | |
| Modificada | Crítica (9.8) | 1.8% | — | Allmediaserver | 29/4/2022 | 17/6/2026 | ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe. | |
| Modificada | Crítica (9.8) | 70% | — | Allmediaserver | 3/4/2022 | 17/6/2026 | Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932. | |
| Modificada | Crítica (9.8) | 1.7% | — | Vitec Exterity AvediaserverVitec Exterity Avediastream Encoders FirmwareVitec Avediastream M9605 FirmwareVitec Avediastream M9400 Firmware+6 | 8/10/2021 | 17/6/2026 | VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root. | |
| Modificada | Media (6.1) | 2.5% | — | Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+19 | 2/10/2019 | 17/6/2026 | faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled. | |
| Modificada | Alta (7.5) | 2.0% | — | Liuyaserver Project Liuyaserver | 7/6/2018 | 17/6/2026 | liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.0% | — | Infraserver Project Infraserver | 7/6/2018 | 17/6/2026 | infraserver is a RESTful server. infraserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Crítica (9.8) | 54% | — | Allmediaserver | 28/12/2017 | 17/6/2026 | A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP port 888. | |
| Modificada | Media (5) | 11% | — | Fireflymediaserver Firefly Media Server | 18/1/2013 | 16/6/2026 | Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2) Accept Language header, (3) User-agent header, (4) Host header, or (5) protocol version; or a (6) crafted HTTP… | |
| Modificada | Media (4.3) | 0.93% | — | Sybase Easerver | 15/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sybase EAServer before 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.2% | — | Invensys DasabcipInvensys Daserver Runtime ComponentsInvensys DassidirectInvensys Intouch/wonderware Application Server+1 | 5/7/2012 | 16/6/2026 | Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and… | |
| Modificada | Media (5) | 64% | — | Sybase Easerver | 9/6/2011 | 16/6/2026 | Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path. | |
| Modificada | Alta (7.8) | 2.2% | — | Sybase Appeon FOR PowerbuilderSybase EaserverSybase Replication ServerSybase Workspace | 20/1/2011 | 16/6/2026 | Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to read arbitrary files via "../\" (dot dot forward-slash backslash) sequences in a crafted request. | |
| Modificada | Alta (10) | 4.5% | — | Sybase Appeon FOR PowerbuilderSybase EaserverSybase Replication ServerSybase Workspace | 20/1/2011 | 16/6/2026 | Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability." | |
| Modificada | Alta (7.5) | 3.7% | — | Fireflymediaserver | 16/4/2008 | 16/6/2026 | Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length. | |
| Modificada | Baja (3.5) | 0.30% | — | Sybase Easerver | 22/5/2006 | 16/6/2026 | Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they are being entered via the GUI, which allows local users to obtain the cleartext passwords via the getSelectedText function in… | |
| Modificada | Media (4) | 1.2% | — | Sybase Easerver | 19/4/2006 | 16/6/2026 | EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles. | |
| Modificada | Alta (7.5) | 1.2% | — | PC Media Miraserver | 20/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php. | |
| Modificada | Media (4.6) | 74% | — | Sybase Easerver | 19/7/2005 | 16/6/2026 | Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter. | |
| Modificada | Alta (10) | 73% | — | SendmailHP Alphaserver SCGentoo LinuxHp-ux+5 | 7/3/2003 | 16/6/2026 | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c. | |
| Modificada | Media (5) | 2.1% | — | Sybase Easerver | 31/12/2002 | 16/6/2026 | Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). | |
| Modificada | Media (5) | 1.6% | — | SUN Javaserver WEB DEV KIT | 18/6/2001 | 16/6/2026 | Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory. | |
| Modificada | Alta (7.2) | 0.54% | — | Hp-uxHP AserverHP 9000 | 2/1/1999 | 16/6/2026 | HP-UX aserver program allows local users to gain privileges via a symlink attack. |