Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.50%—Cobbr CovenantAI16/9/202623/9/2026
Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events,…
Pendiente de análisisAlta (8.6)0.51%—Slovensko.digital AutogramAI19/3/202617/6/2026
Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful…
AplazadaCrítica (9.3)0.43%—Teconceptheme Coven CoreAI20/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven Core coven-core allows Blind SQL Injection.This issue affects Coven Core: from n/a through <= 1.3.
AnalizadaCrítica (9.3)12%—Cobbr Covenant13/1/202617/6/2026
Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.
AplazadaMedia (4.3)0.14%—Straightvisions Gmbh SV Proven ExpertAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in straightvisions GmbH SV Proven Expert sv-provenexpert allows Cross Site Request Forgery.This issue affects SV Proven Expert: from n/a through <= 2.0.06.
AplazadaMedia (5.3)0.39%—OAKAIDenoAIDeno DeployAINodejsAI+29/8/202517/6/2026
oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers.
ModificadaMedia (4.6)0.24%—Huawei Beethoven-w09a FirmwareHuawei Crr-l09 Firmware22/11/201717/6/2026
BTV-W09C229B002CUSTC229D005,BTV-W09C233B029, earlier than BTV-W09C100B006CUSTC100D002 versions, earlier than BTV-W09C128B003CUSTC128D002 versions, earlier than BTV-W09C199B002CUSTC199D002 versions, earlier than BTV-W09C209B005CUSTC209D001 versions, earlier than BTV-W09C331B002CUSTC331D001 versions, earlier than…
ModificadaBaja (3.5)3.0%—IBM Lotus Protector FOR Mail SecurityIBM Proventia Network Mail Security System Firmware27/7/201216/6/2026
Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter.
ModificadaMedia (4.3)2.5%—IBM Proventia Network Mail Security System FirmwareIBM Proventia Network Mail Security SystemIBM Lotus Protector FOR Mail Security20/7/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.
ModificadaBaja (3.5)0.70%—IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware14/9/201016/6/2026
CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.
ModificadaMedia (4)1.3%—IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware14/9/201016/6/2026
Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object…
ModificadaMedia (6.8)0.52%—IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware14/9/201016/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change settings or (2) conduct…
ModificadaMedia (4.3)0.86%—IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware14/9/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via (1) the date1 parameter to pvm_messagestore.php, (2) the…
ModificadaAlta (10)2.3%—IBM Proventia Desktop Endpoint SecurityIBM Proventia Network Mail Security SystemIBM Proventia Network Mail Security System Vitual ApplianceIBM Proventia Network Multi-function Security20/7/200916/6/2026
Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allow remote attackers to bypass…
ModificadaAlta (10)2.7%—IBM Proventia Desktop Endpoint SecurityIBM Proventia Network Mail Security SystemIBM Network Multi-function SecurityIBM Proventia Network Mail Security System Virtual Appliance3/4/200916/6/2026
Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of…
ModificadaAlta (7.1)1.3%—Interwoven Worksite WEB8/4/200816/6/2026
The Web TransferCtrl Class 8,2,1,4 (iManFile.cab), as used in WorkSite Web 8.2 before SP1 P2, allows remote attackers to cause a denial of service (memory consumption) via a large number of SendNrlLink directives, which opens a separate window for each directive.
ModificadaAlta (9.3)4.4%—Interwoven Worksite WEB8/4/200816/6/2026
Double free vulnerability in Web TransferCtrl Class 8,2,1,4 (iManFile.cab), as used in WorkSite Web 8.2 before SP1 P2, allows remote attackers to execute arbitrary code via JavaScript that sets the Server property to a string, then sets the string to null.
ModificadaBaja (3.5)2.2%—IBM Proventia Network IPS Gx5008IBM Proventia Network IPS Gx510817/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.
ModificadaAlta (9.3)4.9%—IBM Proventia Network IPS Gx5008IBM Proventia Network IPS Gx510817/7/200716/6/2026
PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
ModificadaMedia (4.9)0.45%—Republike Slovenije Pirs17/7/200716/6/2026
Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long search string in certain fields in the GUI. NOTE: this may cross privilege boundaries if PIRS is used by data-entry…
ModificadaAlta (7.8)2.0%—ISS Proventia A Series XPUISS Proventia G Series XPUISS Proventia M Series XPU16/5/200716/6/2026
Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
ModificadaAlta (7.5)11%—Web-provence SL Site9/9/200616/6/2026
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition.
ModificadaMedia (5)2.4%—ISS Blackice PC ProtectionISS Blackice Server ProtectionISS Proventia DesktopISS Realsecure Desktop+627/7/200616/6/2026
The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is…
ModificadaBaja (2.6)1.3%—Web-provence SL Site25/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in SL_site 1.0 allows remote attackers to inject arbitrary web script or HTML via the recherche parameter in recherche.php. NOTE: other XSS vectors, as reported in the original disclosure, are resultant from other primary vulnerabilities that have separate CVE names.
ModificadaMedia (5)1.9%—Web-provence SL Site25/4/200616/6/2026
Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.