Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.52%—Vitec AvediaserverAI15/5/202417/6/2026
Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalate privileges via a crafted script.
ModificadaCrítica (9.8)1.8%—Allmediaserver29/4/202217/6/2026
ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.
ModificadaCrítica (9.8)70%—Allmediaserver3/4/202217/6/2026
Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.
ModificadaCrítica (9.8)1.7%—Vitec Exterity AvediaserverVitec Exterity Avediastream Encoders FirmwareVitec Avediastream M9605 FirmwareVitec Avediastream M9400 Firmware+68/10/202117/6/2026
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
ModificadaMedia (6.1)2.5%—Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+192/10/201917/6/2026
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
ModificadaAlta (7.5)2.0%—Liuyaserver Project Liuyaserver7/6/201817/6/2026
liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Infraserver Project Infraserver7/6/201817/6/2026
infraserver is a RESTful server. infraserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaCrítica (9.8)54%—Allmediaserver28/12/201717/6/2026
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP port 888.
ModificadaMedia (5)11%—Fireflymediaserver Firefly Media Server18/1/201316/6/2026
Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2) Accept Language header, (3) User-agent header, (4) Host header, or (5) protocol version; or a (6) crafted HTTP…
ModificadaMedia (4.3)0.93%—Sybase Easerver15/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in Sybase EAServer before 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)2.2%—Invensys DasabcipInvensys Daserver Runtime ComponentsInvensys DassidirectInvensys Intouch/wonderware Application Server+15/7/201216/6/2026
Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and…
ModificadaMedia (5)64%—Sybase Easerver9/6/201116/6/2026
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path.
ModificadaAlta (7.8)2.2%—Sybase Appeon FOR PowerbuilderSybase EaserverSybase Replication ServerSybase Workspace20/1/201116/6/2026
Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to read arbitrary files via "../\" (dot dot forward-slash backslash) sequences in a crafted request.
ModificadaAlta (10)4.5%—Sybase Appeon FOR PowerbuilderSybase EaserverSybase Replication ServerSybase Workspace20/1/201116/6/2026
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability."
ModificadaAlta (7.5)3.7%—Fireflymediaserver16/4/200816/6/2026
Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length.
ModificadaBaja (3.5)0.30%—Sybase Easerver22/5/200616/6/2026
Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they are being entered via the GUI, which allows local users to obtain the cleartext passwords via the getSelectedText function in…
ModificadaMedia (4)1.2%—Sybase Easerver19/4/200616/6/2026
EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles.
ModificadaAlta (7.5)1.2%—PC Media Miraserver20/12/200516/6/2026
Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php.
ModificadaMedia (4.6)74%—Sybase Easerver19/7/200516/6/2026
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.
ModificadaAlta (10)73%—SendmailHP Alphaserver SCGentoo LinuxHp-ux+57/3/200316/6/2026
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
ModificadaMedia (5)2.1%—Sybase Easerver31/12/200216/6/2026
Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
ModificadaMedia (5)1.6%—SUN Javaserver WEB DEV KIT18/6/200116/6/2026
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.
ModificadaAlta (7.2)0.54%—Hp-uxHP AserverHP 90002/1/199916/6/2026
HP-UX aserver program allows local users to gain privileges via a symlink attack.