Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.27% | — | Mozilla Rhino | 3/12/2025 | 17/6/2026 | Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this… | |
| Analizada | Media (6.1) | 0.28% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details. | |
| Analizada | Media (6.1) | 0.33% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a specially crafted URL. | |
| Analizada | Crítica (9.8) | 0.60% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure. | |
| Modificada | Media (6.5) | 2.6% | — | Saltos Rhinos | 16/11/2018 | 17/6/2026 | RhinOS 3.0 build 1190 allows CSRF. | |
| Modificada | Alta (9.3) | 1.6% | — | Rhinosoft FTP Voyager | 3/11/2010 | 16/6/2026 | Directory traversal vulnerability in Rhino Software, Inc. FTP Voyager 15.2.0.11, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. | |
| Modificada | Alta (10) | 21% | — | Rhinosoft Serv-u | 26/5/2010 | 16/6/2026 | Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie. | |
| Modificada | Alta (7.8) | 3.1% | — | Rhinosoft FTP Voyager | 22/2/2007 | 16/6/2026 | Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command, which triggers the overflow when the user aborts the command. | |
| Modificada | Media (4.6) | 0.38% | — | Mozilla RhinoAIApache BatikAI | 14/3/2005 | 16/6/2026 | Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue." | |
| Modificada | Media (4.3) | 1.4% | — | Rhinosoft Dns4me | 18/9/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL. | |
| Modificada | Media (5) | 3.6% | — | Rhinosoft Dns4me | 18/9/2004 | 16/6/2026 | The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data. | |
| Modificada | Media (4.3) | 1.7% | — | Rhinosoft Zaep Antispam | 14/4/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Rhinosoft FTP Voyager | 3/3/2001 | 16/6/2026 | FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands. |