Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 212 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | DeterminedAI | 17/8/2026 | 24/9/2026 | Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own. | |
| Analizada | Media (6.9) | 0.21% | — | Waveterm Wave Terminal | 12/12/2025 | 17/6/2026 | Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2. | |
| Modificada | Alta (8.8) | 4.1% | — | Eterm Project EtermMrxvt Project MrxvtRxvt-unicode Project Rxvt-unicodeRxvt Project Rxvt+2 | 20/5/2021 | 17/6/2026 | rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline. | |
| Modificada | Alta (8.8) | 2.5% | — | Determine Contract Lifecycle Management | 5/1/2020 | 17/6/2026 | An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generating a report, resulting in arbitrary code execution on the underlying server. | |
| Modificada | Media (6.1) | 0.81% | — | Determine Contract Lifecycle Management | 5/1/2020 | 17/6/2026 | An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. A cross-site scripting (XSS) vulnerability in multiple getchart.jsp parameters allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (4.9) | 1.2% | — | Determine Contract Lifecycle Management | 5/1/2020 | 17/6/2026 | An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature in definition_upload_attach.jsp allows authenticated remote attackers to read arbitrary files (including configuration files containing… | |
| Modificada | Alta (7.2) | 1.1% | — | Citrix Deterministic Network Enhancer | 18/11/2008 | 16/6/2026 | dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface. | |
| Modificada | Media (6.9) | 0.31% | — | Eterm | 7/4/2008 | 16/6/2026 | Eterm 0.9.4 opens a terminal window on :0 if -display is not specified and the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine. | |
| Modificada | Baja (3.7) | 0.36% | — | AtermEtermMrxvtMulti-aterm+3 | 7/4/2008 | 16/6/2026 | rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a… | |
| Modificada | Baja (1.2) | 0.73% | — | CetermAIMagnolia CEAI | 3/5/2005 | 16/6/2026 | Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file. | |
| Modificada | Alta (7.2) | 0.50% | — | CetermAI | 3/5/2005 | 16/6/2026 | Buffer overflow in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier may allow local users to gain privileges via a long (1) XAPPLRESLANGPATH or (2) XAPPLRESDIR environment variable, or (3) command line argument. | |
| Modificada | Media (4.6) | 0.38% | — | Michael Jennings EtermDebian Linux | 2/7/2003 | 16/6/2026 | Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable. | |
| Modificada | Media (5) | 1.2% | — | Michael Jennings Eterm | 3/3/2003 | 16/6/2026 | The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence. | |
| Modificada | Alta (7.5) | 1.9% | — | Michael Jennings Eterm | 3/3/2003 | 16/6/2026 | The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary… | |
| Modificada | Media (4.6) | 0.80% | — | Enlightenment ImlibMichael Jennings Eterm | 25/3/2002 | 16/6/2026 | Buffer overflow in Eterm of Enlightenment Imlib2 1.0.4 and earlier allows local users to execute arbitrary code via a long HOME environment variable. | |
| Modificada | Media (5) | 2.5% | — | Michael Jennings EtermPuttyRxvtXfree86 Project X11r6 | 1/6/2000 | 16/6/2026 | xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized. | |
| Modificada | Alta (7.2) | 0.43% | — | Michael Jennings Eterm | 18/2/1999 | 16/6/2026 | Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges. |