Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.52% | — | KdcproxyAI | 12/11/2025 | 30/6/2026 | If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery), they can exploit the fact that kdcproxy does not enforce bounds on TCP response length to conduct a denial-of-service attack. While receiving the KDC's response, kdcproxy copies the entire… | |
| Aplazada | Alta (8.6) | 0.46% | — | KdcproxyAI | 12/11/2025 | 30/6/2026 | If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. This creates a server-side request forgery vulnerability, since an attacker could send a request for a realm matching a… | |
| Modificada | Crítica (9.4) | 1.3% | — | Uninett RadsecproxyFedoraproject Fedora | 28/5/2021 | 17/6/2026 | radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-eduroam.sh` and `radsec-dynsrv.sh` scripts can lead to configuration injection via crafted radsec peer discovery DNS records. Users are subject to Information disclosure,… | |
| Modificada | Alta (7.5) | 2.2% | — | Kdcproxy Project Kdcproxy | 30/10/2018 | 17/6/2026 | python-kdcproxy before 0.3.2 allows remote attackers to cause a denial of service via a large POST request. | |
| Modificada | Media (6.4) | 1.5% | — | Uninett Radsecproxy | 20/11/2012 | 16/6/2026 | The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a… | |
| Modificada | Media (6.4) | 1.8% | — | Uninett Radsecproxy | 20/11/2012 | 16/6/2026 | radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients. | |
| Modificada | Alta (10) | 4.8% | — | Youngzsoft Ccproxy | 6/3/2009 | 16/6/2026 | Buffer overflow in YoungZSoft CCProxy 6.5 might allow remote attackers to execute arbitrary code via a CONNECTION request with a long hostname. | |
| Modificada | Media (5) | 1.7% | — | Dircproxy | 5/10/2007 | 16/6/2026 | irc_server.c in dircproxy 1.2.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via an ACTION command without a parameter, which triggers a NULL pointer dereference, as demonstrated using a blank /me message from irssi. | |
| Modificada | Media (6.4) | 1.9% | — | Computalynx Cproxy | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in Computalynx CProxy 3.3.x and 3.4.x through 3.4.4 allows remote attackers to read arbitrary files or cause a denial of service (application crash) via a .. (dot dot) in an HTTP request. | |
| Modificada | Alta (7.5) | 11% | — | Youngzsoft Ccproxy | 31/12/2004 | 16/6/2026 | Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416. | |
| Modificada | Alta (7.5) | 61% | — | Youngzsoft Ccproxy | 31/12/2004 | 16/6/2026 | Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Media (5) | 2.7% | — | Computalynx Cproxy Server | 16/5/2000 | 16/6/2026 | Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request. |