Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 1.3% | — | Leostream Connection Broker | 18/1/2022 | 17/6/2026 | Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link. | |
| Modificada | Alta (7.2) | 0.96% | — | Leostream Connection Broker | 18/1/2022 | 17/6/2026 | Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code. | |
| Modificada | Media (6.1) | 1.1% | — | Leostream Connection Broker | 6/8/2021 | 17/6/2026 | LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Crítica (9.6) | 2.1% | — | Leostream Connection Broker | 6/10/2020 | 17/6/2026 | Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript code via the webquery.pl User-Agent HTTP header. It is rendered by the admins the next time they log in. The JavaScript injected can be used to force the admin to upload a malicious Perl script that… | |
| Modificada | Alta (7.5) | 1.1% | — | Leostream AgentLeostream Connection Broker | 30/10/2018 | 17/6/2026 | The Leostream Agent before Build 7.0.1.0 when used with Leostream Connection Broker 8.2.72 or earlier allows remote attackers to modify registry keys via the Leostream Agent API. |