Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.28% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details. | |
| Analizada | Media (6.1) | 0.33% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a specially crafted URL. | |
| Analizada | Crítica (9.8) | 0.60% | — | Saltos Rhinos | 27/5/2024 | 17/6/2026 | A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure. | |
| Modificada | Media (6.5) | 2.6% | — | Saltos Rhinos | 16/11/2018 | 17/6/2026 | RhinOS 3.0 build 1190 allows CSRF. | |
| Modificada | Alta (9.3) | 1.6% | — | Rhinosoft FTP Voyager | 3/11/2010 | 16/6/2026 | Directory traversal vulnerability in Rhino Software, Inc. FTP Voyager 15.2.0.11, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. | |
| Modificada | Alta (10) | 21% | — | Rhinosoft Serv-u | 26/5/2010 | 16/6/2026 | Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie. | |
| Modificada | Alta (7.8) | 3.1% | — | Rhinosoft FTP Voyager | 22/2/2007 | 16/6/2026 | Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command, which triggers the overflow when the user aborts the command. | |
| Modificada | Media (4.3) | 1.4% | — | Rhinosoft Dns4me | 18/9/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL. | |
| Modificada | Media (5) | 3.6% | — | Rhinosoft Dns4me | 18/9/2004 | 16/6/2026 | The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data. | |
| Modificada | Media (4.3) | 1.7% | — | Rhinosoft Zaep Antispam | 14/4/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Rhinosoft FTP Voyager | 3/3/2001 | 16/6/2026 | FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands. |