Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Alienvault Open Source Security Information Management27/1/202016/6/2026
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
ModificadaCrítica (9.8)2.4%—Alienvault Open Source Security Information ManagementAlienvault Unified Security Management14/3/201817/6/2026
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
ModificadaAlta (7.2)2.7%—Alienvault Open Source Security Information Management23/5/201717/6/2026
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php.
ModificadaMedia (6.7)0.51%—Alienvault Open Source Security Information Management23/5/201717/6/2026
The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script.
ModificadaMedia (6.5)21%—Alienvault Open Source Security Information Management21/8/201417/6/2026
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (10)15%—Alienvault Open Source Security Information Management21/8/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.
ModificadaAlta (7.5)1.3%—Alienvault Open Source Security Information Management21/8/201417/6/2026
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter.
ModificadaAlta (10)3.7%—Alienvault Open Source Security Information Management21/8/201417/6/2026
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.
ModificadaAlta (7.8)7.4%—Alienvault Open Source Security Information Management18/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.
ModificadaAlta (10)5.8%—Alienvault Open Source Security Information Management18/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key.
ModificadaAlta (10)7.3%—Alienvault Open Source Security Information Management18/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request.
ModificadaAlta (10)13%—Alienvault Open Source Security Information Management13/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804.
ModificadaAlta (10)72%—Alienvault Open Source Security Information Management13/6/201417/6/2026
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4) sync_rserver, or (5) set_ossim_setup framework_ip request, a different vulnerability than…
ModificadaAlta (7.5)19%—Alienvault Open Source Security Information Management9/10/201316/6/2026
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3)…
ModificadaAlta (7.5)1.4%—Alienvault Open Source Security Information Management20/8/201316/6/2026
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to…
ModificadaMedia (4.3)1.8%—Alienvault Open Source Security Information Management15/8/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to…
ModificadaMedia (4.3)2.2%—Alienvault Open Source Security Information Management3/7/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an…
ModificadaMedia (6.5)1.4%—Alienvault Open Source Security Information Management3/7/201216/6/2026
SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter.
ModificadaAlta (7.5)0.97%—Alienvault Open Source Security Information Management21/12/200916/6/2026
SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary SQL commands via the id_document parameter.
ModificadaAlta (7.5)1.6%—Alienvault Open Source Security Information Management21/12/200916/6/2026
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.
ModificadaAlta (7.5)3.0%—Alienvault Open Source Security Information Management21/12/200916/6/2026
Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a…
ModificadaAlta (7.5)4.8%—Alienvault Open Source Security Information Management21/12/200916/6/2026
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the uniqueid parameter to (1) wcl.php, (2) storage_graphs.php, (3) storage_graphs2.php, (4) storage_graphs3.php, and (5)…
ModificadaMedia (4.3)3.7%—Open Source Security Information Management Os-sim22/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter.
ModificadaMedia (6.5)1.0%—Open Source Security Information Management Os-sim22/2/200816/6/2026
SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.