Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.39% | — | Tigrisflexplatform Tigris-flexplatformAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tigrisflexplatform Tigris Flexplatform tigris-flexplatform allows Stored XSS.This issue affects Tigris Flexplatform: from n/a through <= 1.0.2. | |
| Modificada | Media (5.9) | 5.8% | — | PuttyFilezilla-project Filezilla ClientWinscpTortoisegit+2 | 15/4/2024 | 17/6/2026 | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of… | |
| Modificada | Alta (9.3) | 4.2% | — | Tigris Tortoisesvn | 10/9/2010 | 16/6/2026 | Untrusted search path vulnerability in TortoiseSVN 1.6.10, Build 19898 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Tortoise. NOTE: this is only… | |
| Modificada | Baja (3.5) | 1.6% | — | Tigris Websvn | 21/1/2009 | 16/6/2026 | listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | Tigris Websvn | 21/1/2009 | 16/6/2026 | The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function with the eval switch. | |
| Modificada | Media (6.8) | 6.3% | — | Tigris Websvn | 21/1/2009 | 16/6/2026 | Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to overwrite arbitrary files via directory traversal sequences in the rev parameter. | |
| Modificada | Media (4.3) | 4.5% | — | Tigris Websvn | 21/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Media (5) | 1.3% | — | Ericsson AXC Tigris Multiservice Access Platform | 13/6/2000 | 16/6/2026 | Tigris remote access server before 11.5.4.22 does not properly record Radius accounting information when a user fails the initial login authentication but subsequently succeeds. | |
| Modificada | Alta (7.5) | 1.1% | — | ACC Tigris | 2/2/1999 | 16/6/2026 | ACC Tigris allows public access without a login. |