Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.72%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.
ModificadaMedia (5.4)0.56%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.
ModificadaAlta (7.5)1.4%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files.
ModificadaAlta (7.5)1.5%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive information via info.php4.
ModificadaAlta (8.8)0.51%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.
ModificadaAlta (8.8)1.1%—Castlerock Snmpc10/4/201717/6/2026
Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
ModificadaMedia (6.1)0.78%—Castlerock Snmpc10/4/201717/6/2026
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.
ModificadaAlta (10)8.8%—Castle Rock Snmpc14/5/200816/6/2026
Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long community string in an SNMP TRAP packet.
ModificadaMedia (5)3.6%—Castle Rock Computing Snmpc6/6/200716/6/2026
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a crafted packet to port 165/TCP.
ModificadaAlta (10)2.5%—Castle Rock Computing Snmpc20/10/200316/6/2026
SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.