Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.68% | — | Exlibrisgroup Aleph 500 | 10/3/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component cgi-bin/ej.cgi of Ex libris ALEPH 500 v18.1 and v20 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Crítica (9.8) | 2.0% | — | Exlibrisgroup Aleph 500 | 30/1/2020 | 17/6/2026 | Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to execute arbitrary SQL commands via the (1) find, (2) lib, or (3) sid parameter. | |
| Modificada | Media (6.1) | 0.97% | — | Exlibrisgroup Aleph 500 | 30/1/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to inject arbitrary web script or HTML via the (1) find, (2) lib, or (3) sid parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Progress Mixlib-archive | 17/7/2017 | 17/6/2026 | Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries | |
| Modificada | Baja (2.6) | 1.3% | — | Exlibris Group Metalib | 17/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Ex Libris MetaLib 3.13 and 4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a resource id that can be discovered through a search. | |
| Modificada | Media (4.3) | 1.1% | — | Exlibris Group Aleph | 17/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Ex Libris ALEPH allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a URL that can be discovered through a keyword search. NOTE: this may be related to the MetaLib XSS issue, CVE-2007-3835. | |
| Modificada | Alta (7.2) | 0.45% | — | X.org Emu-linux-x87-xlibsX.org X11r6X.org X11r7X.org XDM+5 | 30/8/2006 | 16/6/2026 | X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit. | |
| Modificada | Media (4.6) | 0.97% | — | Xfree86 Project Xlib | 19/12/2000 | 23/9/2026 | Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter. |