Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Snoopy Project Snoopy28/10/201916/6/2026
Snoopy before 2.0.0 has a security hole in exec cURL
ModificadaCrítica (9.8)4.7%—SnoopyRedhat OpenstackNagios31/3/201717/6/2026
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
ModificadaCrítica (9.8)4.1%—SnoopyRedhat OpenstackDebian Linux31/3/201717/6/2026
Snoopy allows remote attackers to execute arbitrary commands.
ModificadaCrítica (9.8)4.5%—SnoopyRedhat OpenstackNagios31/3/201716/6/2026
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
ModificadaMedia (4.3)1.3%—SnoopyMoodle10/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as"…
ModificadaAlta (10)9.0%—Snoopy Project SnoopyDebian LinuxNagiosWordpress30/10/200816/6/2026
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
ModificadaMedia (6.8)31%—Electronic Arts Snoopyctrl9/10/200716/6/2026
Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters.
ModificadaAlta (7.5)17%—Snoopy27/10/200516/6/2026
The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.