Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.54% | — | WsgidavAI | 28/8/2026 | 9/9/2026 | WsgiDAV is a generic and extendable WebDAV server based on WSGI. Prior to 4.3.5, the sample MySQLBrowserProvider in wsgidav/samples/mysql_dav_provider.py concatenates the record key parsed from a request URL directly into SQL WHERE clauses. The affected _exists_record_by_primary_key, _get_field_by_primary_key, and… | |
| Aplazada | Alta (7.1) | 0.41% | — | WsgidavAI | 13/8/2026 | 9/9/2026 | WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4. | |
| Aplazada | Media (5.5) | 0.26% | — | SGI Performance Co-pilotAI | 19/9/2024 | 17/6/2026 | A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash. | |
| Modificada | Media (6.7) | 0.20% | — | SGI Performance Co-pilotRedhat Enterprise Linux | 28/2/2024 | 17/6/2026 | A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in… | |
| Modificada | Media (4.8) | 0.42% | — | Idemia Sgima Lite & Lite+ FirmwareIdemia Sigma Wide FirmwareIdemia Sigma Extreme FirmwareIdemia Morphowave Compact Firmware+2 | 28/11/2023 | 17/6/2026 | The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface. The root cause of the vulnerability is inadequate input validation and… | |
| Modificada | Alta (7.8) | 0.17% | — | HPE SGI UV 300 RMC FirmwareHPE Integrity Mc990 X Server RMC Firmware | 16/6/2023 | 17/6/2026 | The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privilege. | |
| Analizada | Alta (7.5) | 2.1% | — | Apache Http ServerDebian LinuxUnbit Uwsgi | 7/3/2023 | 17/6/2026 | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. | |
| Modificada | Media (6.1) | 0.37% | — | Wsgidav Project Wsgidav | 11/11/2022 | 17/6/2026 | WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. This issue has been patched, users can upgrade to version 4.1.0. As a workaround, set `dir_browser.enable = False` in the… | |
| Modificada | Alta (7.5) | 0.88% | — | Modwsgi MOD WsgiDebian Linux | 25/8/2022 | 17/6/2026 | A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing. | |
| Modificada | Alta (8.8) | 3.1% | — | Netsurf-browser Libnsgif | 18/2/2020 | 17/6/2026 | Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file. | |
| Modificada | Media (6.5) | 1.3% | — | Netsurf-browser Libnsgif | 18/2/2020 | 17/6/2026 | The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file. | |
| Modificada | Alta (7.8) | 0.70% | — | HP SGI Tempo | 27/1/2020 | 17/6/2026 | SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db. | |
| Modificada | Alta (7.8) | 0.56% | — | HP SGI Tempo | 27/1/2020 | 17/6/2026 | SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx. | |
| Modificada | Media (6.6) | 0.51% | — | HP SGI Tempo | 27/1/2020 | 17/6/2026 | SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw. | |
| Modificada | Alta (7.5) | 8.5% | — | Modwsgi MOD Wsgi | 9/12/2019 | 17/6/2026 | mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread. | |
| Modificada | Media (6.1) | 0.68% | — | Sgin Xiangyun Platform | 6/6/2018 | 17/6/2026 | SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php. | |
| Modificada | Alta (7.5) | 69% | — | Unbit UwsgiDebian Linux | 26/2/2018 | 17/6/2026 | uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal. | |
| Modificada | Crítica (9.8) | 2.0% | — | Unbit Uwsgi | 6/2/2018 | 17/6/2026 | The uwsgi_expand_path function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a large directory length. | |
| Modificada | Media (5) | 4.5% | — | SGI Xfsprogs | 25/8/2015 | 16/6/2026 | xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading a generated image. | |
| Modificada | Media (6.9) | 0.40% | — | Modwsgi MOD Wsgi | 16/12/2014 | 17/6/2026 | mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors. | |
| Modificada | Media (6.2) | 0.41% | — | Modwsgi MOD Wsgi | 27/5/2014 | 17/6/2026 | The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes. | |
| Modificada | Baja (2.1) | 0.37% | — | SGI Performance Co-pilot | 29/11/2012 | 16/6/2026 | The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file. | |
| Modificada | Media (5) | 3.3% | — | SGI Performance Co-pilot | 27/8/2012 | 16/6/2026 | The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw." | |
| Modificada | Media (5) | 2.4% | — | SGI Performance Co-pilot | 27/8/2012 | 16/6/2026 | Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in… | |
| Modificada | Media (5) | 1.8% | — | SGI Performance Co-pilot | 27/8/2012 | 16/6/2026 | Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments. |