Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.32% | — | Easyvirt DcscopeAIEasyvirt Co2scopeAI | 25/4/2025 | 17/6/2026 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) timeago, (2) user, (3) filter, (4) target, (5) p1, (6) p2, (7) p3, (8) p4, (9) p5, (10) p6, (11) p7, (12) p8, (13) p9, (14) p10, (15) p11, (16)… | |
| Analizada | Crítica (9.1) | 0.58% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login. | |
| Analizada | Crítica (9.8) | 1.1% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/. | |
| Analizada | Alta (7.5) | 0.51% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/updatealiasroute; (4) delete users via the /api/user/delalias route; (4)… | |
| Analizada | Crítica (9.8) | 0.66% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". A weak HMAC secret poses a risk because attackers can use the predictable secret to… | |
| Analizada | Alta (8.8) | 0.55% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/updatealias route; (4) delete users via the /api/user/delalias route;… | |
| Analizada | Media (6.5) | 0.50% | — | Easyvirt Co2scopeEasyvirt Dcscope | 31/1/2025 | 17/6/2026 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) user parameter to /api/management/findfilterlist; the (2) user or (3) filter parameter to /api/audit/findmetawatcher; the (4) user parameter to… | |
| Modificada | Alta (9.3) | 7.5% | — | Cscope | 7/5/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file. | |
| Modificada | Alta (9.3) | 6.8% | — | Cscope | 5/5/2009 | 16/6/2026 | Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541. | |
| Modificada | Media (5.1) | 4.0% | — | Cscope | 23/8/2006 | 16/6/2026 | Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable… | |
| Modificada | Baja (2.1) | 1.1% | — | CscopeDebian LinuxGentoo LinuxSCO Unixware | 10/1/2005 | 16/6/2026 | main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Media (6.9) | 1.7% | — | Cscope | 31/12/2004 | 16/6/2026 | Buffer overflow in Cscope 15.5, and possibly multiple overflows, allows remote attackers to execute arbitrary code via a C file with a long #include line that is later browsed by the target. |