Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
–

275 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.54%—WsgidavAI28/8/20269/9/2026
WsgiDAV is a generic and extendable WebDAV server based on WSGI. Prior to 4.3.5, the sample MySQLBrowserProvider in wsgidav/samples/mysql_dav_provider.py concatenates the record key parsed from a request URL directly into SQL WHERE clauses. The affected _exists_record_by_primary_key, _get_field_by_primary_key, and…
AplazadaAlta (7.1)0.41%—WsgidavAI13/8/20269/9/2026
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.
AplazadaMedia (5.5)0.26%—SGI Performance Co-pilotAI19/9/202417/6/2026
A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
ModificadaMedia (6.7)0.20%—SGI Performance Co-pilotRedhat Enterprise Linux28/2/202417/6/2026
A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in…
ModificadaMedia (4.8)0.42%—Idemia Sgima Lite & Lite+ FirmwareIdemia Sigma Wide FirmwareIdemia Sigma Extreme FirmwareIdemia Morphowave Compact Firmware+228/11/202317/6/2026
The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface. The root cause of the vulnerability is inadequate input validation and…
ModificadaAlta (7.8)0.17%—HPE SGI UV 300 RMC FirmwareHPE Integrity Mc990 X Server RMC Firmware16/6/202317/6/2026
The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privilege.
AnalizadaAlta (7.5)2.1%—Apache Http ServerDebian LinuxUnbit Uwsgi7/3/202317/6/2026
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
ModificadaMedia (6.1)0.37%—Wsgidav Project Wsgidav11/11/202217/6/2026
WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. This issue has been patched, users can upgrade to version 4.1.0. As a workaround, set `dir_browser.enable = False` in the…
ModificadaAlta (7.5)0.88%—Modwsgi MOD WsgiDebian Linux25/8/202217/6/2026
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.
ModificadaAlta (8.8)3.1%—Netsurf-browser Libnsgif18/2/202017/6/2026
Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.
ModificadaMedia (6.5)1.3%—Netsurf-browser Libnsgif18/2/202017/6/2026
The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file.
ModificadaAlta (7.8)0.70%—HP SGI Tempo27/1/202017/6/2026
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.
ModificadaAlta (7.8)0.56%—HP SGI Tempo27/1/202017/6/2026
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.
ModificadaMedia (6.6)0.51%—HP SGI Tempo27/1/202017/6/2026
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw.
ModificadaAlta (7.5)8.5%—Modwsgi MOD Wsgi9/12/201917/6/2026
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
ModificadaMedia (6.1)0.68%—Sgin Xiangyun Platform6/6/201817/6/2026
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.
ModificadaAlta (7.5)69%—Unbit UwsgiDebian Linux26/2/201817/6/2026
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
ModificadaCrítica (9.8)2.0%—Unbit Uwsgi6/2/201817/6/2026
The uwsgi_expand_path function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a large directory length.
ModificadaMedia (5)4.5%—SGI Xfsprogs25/8/201516/6/2026
xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading a generated image.
ModificadaMedia (6.9)0.40%—Modwsgi MOD Wsgi16/12/201417/6/2026
mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors.
ModificadaMedia (6.2)0.41%—Modwsgi MOD Wsgi27/5/201417/6/2026
The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes.
ModificadaBaja (2.1)0.37%—SGI Performance Co-pilot29/11/201216/6/2026
The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.
ModificadaMedia (5)3.3%—SGI Performance Co-pilot27/8/201216/6/2026
The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw."
ModificadaMedia (5)2.4%—SGI Performance Co-pilot27/8/201216/6/2026
Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in…
ModificadaMedia (5)1.8%—SGI Performance Co-pilot27/8/201216/6/2026
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.