Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
283 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects GYM Management System IN PHPAIMicrosoft Windows NTAI | 4/5/2026 | 17/6/2026 | A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /index.php. Performing a manipulation of the argument day results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |
| Modificada | Alta (9.3) | 32% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 26/11/2008 | 16/6/2026 | Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the… | |
| Modificada | Alta (9.3) | 37% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+10 | 11/9/2008 | 16/6/2026 | Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006,… | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+12 | 11/9/2008 | 16/6/2026 | gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000… | |
| Modificada | Alta (9.3) | 55% | 💥 Exploit | Microsoft Windows Media EncoderMicrosoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 Server+1 | 11/9/2008 | 16/6/2026 | Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability." | |
| Modificada | Alta (9.3) | 53% | 💥 Exploit | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+12 | 11/9/2008 | 16/6/2026 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000… | |
| Modificada | Alta (9) | 36% | — | Microsoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Vista+1 | 13/8/2008 | 16/6/2026 | The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request. | |
| Modificada | Alta (9) | 28% | — | Microsoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Vista+1 | 13/8/2008 | 16/6/2026 | Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers. | |
| Modificada | Alta (7.8) | 32% | — | Microsoft Windows-ntMicrosoft Windows Vista | 13/8/2008 | 16/6/2026 | Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions. | |
| Modificada | Alta (9.3) | 29% | — | Microsoft Windows-ntMicrosoft Windows Vista | 8/7/2008 | 16/6/2026 | Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability." | |
| Modificada | Alta (8.3) | 2.4% | — | Microsoft Windows-ntMicrosoft Windows VistaMicrosoft Windows XP | 12/6/2008 | 16/6/2026 | The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via a large series of Service Discovery Protocol (SDP) packets. | |
| Modificada | Alta (7.1) | 27% | — | Microsoft Windows-ntMicrosoft Windows 2003 ServerMicrosoft Windows XP | 12/6/2008 | 16/6/2026 | Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request. | |
| Modificada | Alta (9) | 37% | 💥 Exploit | Microsoft Windows-ntMicrosoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 21/4/2008 | 16/6/2026 | Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has… | |
| Modificada | Media (5) | 70% | 💥 Exploit | Microsoft Windows-nt | 14/4/2008 | 16/6/2026 | dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values. NOTE: this might be similar to CVE-2008-1777. | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Internet ExplorerMicrosoft Windows-ntMicrosoft Windows 2003 ServerMicrosoft Windows Vista+1 | 8/4/2008 | 16/6/2026 | The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption. | |
| Modificada | Alta (9.3) | 57% | 💥 Exploit | Microsoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Vista+1 | 8/4/2008 | 16/6/2026 | Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability." | |
| Modificada | Alta (9.3) | 28% | 💥 Exploit | Microsoft JETMicrosoft OfficeMicrosoft Windows 2000Microsoft Windows 2003 Server+2 | 20/11/2007 | 16/6/2026 | Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be… | |
| Modificada | Media (6.9) | 1.5% | — | Microsoft Windows NT | 11/4/2007 | 16/6/2026 | Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206. | |
| Modificada | Media (6.8) | 11% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 10/4/2007 | 16/6/2026 | Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file. | |
| Modificada | Alta (9.3) | 8.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+19 | 8/2/2007 | 16/6/2026 | Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable. | |
| Modificada | Baja (2.6) | 80% | 💥 Exploit | Microsoft Windows NT Helper ComponentsMicrosoft Windows XP | 31/10/2006 | 16/6/2026 | Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference. | |
| Modificada | Alta (9.3) | 54% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 13/6/2006 | 16/6/2026 | Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing. | |
| Modificada | Alta (7.5) | 31% | — | Microsoft Distributed Transaction CoordinatorMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NT+1 | 10/5/2006 | 16/6/2026 | Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode,… | |
| Modificada | Media (5) | 30% | — | Microsoft Distributed Transaction CoordinatorMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NT+1 | 10/5/2006 | 16/6/2026 | Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the… | |
| Modificada | Media (5.1) | 7.1% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 3/4/2006 | 16/6/2026 | Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a .hlp file. |