Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.28%—Saltos Rhinos27/5/202417/6/2026
RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details.
AnalizadaMedia (6.1)0.33%—Saltos Rhinos27/5/202417/6/2026
Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a specially crafted URL.
AnalizadaCrítica (9.8)0.60%—Saltos Rhinos27/5/202417/6/2026
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure.
ModificadaMedia (6.5)2.6%—Saltos Rhinos16/11/201817/6/2026
RhinOS 3.0 build 1190 allows CSRF.
ModificadaAlta (9.3)1.6%—Rhinosoft FTP Voyager3/11/201016/6/2026
Directory traversal vulnerability in Rhino Software, Inc. FTP Voyager 15.2.0.11, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
ModificadaAlta (10)21%—Rhinosoft Serv-u26/5/201016/6/2026
Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.
ModificadaAlta (7.8)3.1%—Rhinosoft FTP Voyager22/2/200716/6/2026
Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command, which triggers the overflow when the user aborts the command.
ModificadaMedia (4.3)1.4%—Rhinosoft Dns4me18/9/200416/6/2026
Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.
ModificadaMedia (5)3.6%—Rhinosoft Dns4me18/9/200416/6/2026
The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.
ModificadaMedia (4.3)1.7%—Rhinosoft Zaep Antispam14/4/200416/6/2026
Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.
ModificadaAlta (7.5)2.1%—Rhinosoft FTP Voyager3/3/200116/6/2026
FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands.