Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Alienvault Open Source Security Information Management | 27/1/2020 | 16/6/2026 | OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability | |
| Modificada | Crítica (9.8) | 2.4% | — | Alienvault Open Source Security Information ManagementAlienvault Unified Security Management | 14/3/2018 | 17/6/2026 | A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1. | |
| Modificada | Alta (7.2) | 2.7% | — | Alienvault Open Source Security Information Management | 23/5/2017 | 17/6/2026 | The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php. | |
| Modificada | Media (6.7) | 0.51% | — | Alienvault Open Source Security Information Management | 23/5/2017 | 17/6/2026 | The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script. | |
| Modificada | Media (6.5) | 21% | — | Alienvault Open Source Security Information Management | 21/8/2014 | 17/6/2026 | SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (10) | 15% | — | Alienvault Open Source Security Information Management | 21/8/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805. | |
| Modificada | Alta (7.5) | 1.3% | — | Alienvault Open Source Security Information Management | 21/8/2014 | 17/6/2026 | SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter. | |
| Modificada | Alta (10) | 3.7% | — | Alienvault Open Source Security Information Management | 21/8/2014 | 17/6/2026 | The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors. | |
| Modificada | Alta (7.8) | 7.4% | — | Alienvault Open Source Security Information Management | 18/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request. | |
| Modificada | Alta (10) | 5.8% | — | Alienvault Open Source Security Information Management | 18/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key. | |
| Modificada | Alta (10) | 7.3% | — | Alienvault Open Source Security Information Management | 18/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request. | |
| Modificada | Alta (10) | 13% | — | Alienvault Open Source Security Information Management | 13/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804. | |
| Modificada | Alta (10) | 72% | — | Alienvault Open Source Security Information Management | 13/6/2014 | 17/6/2026 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4) sync_rserver, or (5) set_ossim_setup framework_ip request, a different vulnerability than… | |
| Modificada | Alta (7.5) | 19% | — | Alienvault Open Source Security Information Management | 9/10/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3)… | |
| Modificada | Alta (7.5) | 1.4% | — | Alienvault Open Source Security Information Management | 20/8/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to… | |
| Modificada | Media (4.3) | 1.8% | — | Alienvault Open Source Security Information Management | 15/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to… | |
| Modificada | Media (4.3) | 2.2% | — | Alienvault Open Source Security Information Management | 3/7/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an… | |
| Modificada | Media (6.5) | 1.4% | — | Alienvault Open Source Security Information Management | 3/7/2012 | 16/6/2026 | SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Alienvault Open Source Security Information Management | 21/12/2009 | 16/6/2026 | SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary SQL commands via the id_document parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Alienvault Open Source Security Information Management | 21/12/2009 | 16/6/2026 | Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | Alienvault Open Source Security Information Management | 21/12/2009 | 16/6/2026 | Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a… | |
| Modificada | Alta (7.5) | 4.8% | — | Alienvault Open Source Security Information Management | 21/12/2009 | 16/6/2026 | AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the uniqueid parameter to (1) wcl.php, (2) storage_graphs.php, (3) storage_graphs2.php, (4) storage_graphs3.php, and (5)… | |
| Modificada | Media (4.3) | 3.7% | — | Open Source Security Information Management Os-sim | 22/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter. | |
| Modificada | Media (6.5) | 1.0% | — | Open Source Security Information Management Os-sim | 22/2/2008 | 16/6/2026 | SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression. |