Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 93 respecto a la semana anterior
Críticas / altas1464▲ 354 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 418 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.20%—Nsasoft Blueauditor12/4/202617/6/2026
BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registration field, causing the…
AnalizadaMedia (6.9)0.24%—Nsasoft Spotauditor5/4/202624/7/2026
SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.
AnalizadaAlta (8.6)0.25%—Nsasoft Nsauditor26/3/202617/6/2026
Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field to achieve code…
AnalizadaMedia (6.9)0.24%—Nsasoft Nsauditor22/3/202617/6/2026
NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function to cause a denial of service condition.
AnalizadaMedia (6.9)0.19%—Nsasoft Spotauditor22/3/202617/6/2026
SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 repeated characters into the Name input during registration to trigger an…
AnalizadaMedia (6.7)0.32%—Nsasoft Spotauditor20/2/202629/6/2026
SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field during registration to trigger an unhandled…
AnalizadaMedia (6.7)0.45%—Nsasoft Spotauditor12/2/202617/6/2026
SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application crash when pasted into the Base64…
AnalizadaAlta (8.4)0.22%—Nsasoft Spotauditor12/2/202617/6/2026
SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured Exception Handler (SEH) overwrite and execute…
AplazadaMedia (4.6)0.32%—Nsasoft BlueauditorAI11/2/202617/6/2026
BlueAuditor 1.7.2.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.
AnalizadaMedia (6.7)0.48%—Nsasoft Nsauditor5/2/202617/6/2026
Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the registration name field.
AnalizadaAlta (8.4)0.65%—Nsasoft Nsauditor5/2/202617/6/2026
Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute shellcode through a carefully constructed…
AnalizadaMedia (6.7)0.35%—Nsasoft Nsauditor23/1/202617/6/2026
Nsauditor 3.2.2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Event Description field with a large buffer. Attackers can generate a 10,000-character 'U' buffer and paste it into the Event Description field to trigger an application crash.
AnalizadaMedia (6.7)0.48%—Nsasoft Nsauditor16/1/202617/6/2026
Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can paste a large buffer of 256 repeated characters into the 'Key' field to trigger an application crash.
AnalizadaAlta (8.5)0.25%—Brother Brprint Auditor16/1/202617/6/2026
Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted file paths in BrAuSvc and BRPA_Agent services to inject malicious executables and escalate privileges…
AnalizadaMedia (6.1)0.45%—Damienharper Auditor-bundle10/9/202417/6/2026
auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because `%source_label%` in twig macro is not escaped. Therefore script tags can be inserted…
AnalizadaCrítica (9.8)36%⚠ Explotación activaNetwrix Auditor8/11/202217/6/2026
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an…
ModificadaMedia (6.1)0.81%—Mcafee Policy Auditor23/11/202117/6/2026
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extract…
ModificadaMedia (6.1)0.82%—Mcafee Policy Auditor23/11/202117/6/2026
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the profileNodeID request parameters. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to…
AnalizadaMedia (5.5)0.72%—Nsasoft Spotauditor2/11/202129/6/2026
An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering.
ModificadaMedia (4.2)2.5%—OpenldapRedhat Enterprise LinuxOpensuse LeapMcafee Policy Auditor+114/7/202017/6/2026
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
ModificadaMedia (6.5)4.3%—SqliteNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Oncommand Insight+169/9/201917/6/2026
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
ModificadaAlta (7.8)0.47%—Netwrix Auditor12/8/201917/6/2026
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to that directory) does not perform proper impersonation, and thus the target file will have the same permissions as the…
ModificadaMedia (4.9)3.4%—OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+526/7/201917/6/2026
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from…
ModificadaMedia (5.4)0.64%—Chartered Accountant \ Auditor Website Project6/6/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.
ModificadaMedia (6.5)1.4%—Chartered Accountant \ Auditor Website Project21/3/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.