Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2667▼ 241 respecto a la semana anterior
Críticas / altas1361▲ 103 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | Dromara NorthstarAI | 5/10/2026 | 5/10/2026 | Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via… | |
| Aplazada | Media (5.3) | 0.31% | — | Dromara NorthstarAI | 14/7/2025 | 17/6/2026 | A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument… | |
| Aplazada | Alta (8.8) | 78% | — | Egindemirbilek Northstar C2AI | 6/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component. | |
| Modificada | Crítica (9.8) | 0.93% | — | Globalnorthstar Northstar Club Management | 16/9/2022 | 17/6/2026 | There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the… | |
| Modificada | Media (5.3) | 1.8% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application. | |
| Modificada | Alta (7.5) | 0.81% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP. | |
| Modificada | Crítica (9.8) | 1.7% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication. | |
| Modificada | Alta (7.5) | 1.8% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application. | |
| Modificada | Media (6.5) | 0.81% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request. | |
| Modificada | Crítica (9.8) | 3.6% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters. | |
| Modificada | Media (5.5) | 0.29% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread denials of service to system services by consuming TCP and UDP ports which are normally reserved for other system services. | |
| Modificada | Alta (7.5) | 0.97% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to perform a man-in-the-middle attack, thereby stealing authentic credentials from encrypted paths which are easily decrypted, and subsequently gain… | |
| Modificada | Media (6.5) | 1.1% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A persistent denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network-based, authenticated attacker to consume enough system resources to cause a persistent denial of service by visiting certain specific URLs on the server. | |
| Modificada | Alta (8.8) | 2.3% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network based, unauthenticated attacker to perform privileged actions to gain complete control over the environment. | |
| Modificada | Alta (7.3) | 1.1% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A firewall bypass vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to bypass firewall policies, leading to authentication bypass methods, information disclosure, modification of system files, and denials of service. | |
| Modificada | Media (6.2) | 0.32% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbit virus, or wabbit, which will create processes that replicate themselves, until all resources are… | |
| Modificada | Media (6.2) | 0.36% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivileged system files capable of causing widespread denials of system services. | |
| Modificada | Media (5.5) | 0.32% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to elevate their permissions through reading unprivileged information stored in the NorthStar controller. | |
| Modificada | Media (5.5) | 0.30% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to consume large amounts of system resources leading to a cascading denial of services. | |
| Modificada | Media (6.5) | 1.1% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, network-based attacker to replicate the underlying Junos OS VM and all data it maintains to their local system for future analysis. | |
| Modificada | Media (6.5) | 1.2% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service. | |
| Modificada | Media (5.3) | 2.0% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to cause a denial of service condition. | |
| Modificada | Alta (7.5) | 1.3% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker crafting packets destined to the device to cause a persistent denial of service to the path computation server service. | |
| Modificada | Alta (8.6) | 1.5% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of… | |
| Modificada | Crítica (10) | 1.9% | — | Juniper Northstar Controller | 24/4/2017 | 17/6/2026 | A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including… |