Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 100% | — | Ahnlab V3 Internet SecurityAladdin EsafeAlwil Avast AntivirusAnti-virus Vba32+31 | 21/3/2012 | 16/6/2026 | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools… | |
| Modificada | Media (4.3) | 93% | — | Antiy AVL SDKAvira AntivirCAT Quick HealEmsisoft Anti-malware+12 | 21/3/2012 | 16/6/2026 | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus… | |
| Modificada | Media (5.8) | 0.96% | — | Nathanielkh Limit MY Call | 25/1/2012 | 16/6/2026 | The Limit My Call (com.limited.call.view) application 2.11 for Android does not properly protect data, which allows remote attackers to read or modify call logs and a contact list via a crafted application. | |
| Modificada | Media (5.8) | 0.96% | — | Hatena Callconfirm | 25/1/2012 | 16/6/2026 | The CallConfirm (jp.gr.java_conf.ofnhwx.callconfirm) application 2.0.0 for Android does not properly protect data, which allows remote attackers to read or modify allow/block lists via a crafted application. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Alta (7.8) | 2.9% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 28/9/2009 | 16/6/2026 | Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vicidial Call Center Suite | 27/6/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to execute arbitrary SQL commands via the (1) Username parameter ($PHP_AUTH_USER) and (2) Password parameter ($PHP_AUTH_PW). | |
| Modificada | Media (5) | 1.9% | — | Drupal Semantically Interconnected Online Communities | 18/2/2009 | 16/6/2026 | Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Codecall COM Ionfiles | 6/2/2009 | 16/6/2026 | Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Alta (9.3) | 7.0% | — | Trend Micro Housecall | 23/12/2008 | 16/6/2026 | Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function. | |
| Modificada | Alta (9.3) | 7.0% | — | Trend Micro Housecall | 23/12/2008 | 16/6/2026 | The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to download an arbitrary library file onto a client system via a "custom update server" argument. NOTE: this can be leveraged for code execution by writing to a Startup folder. | |
| Modificada | Alta (7.1) | 3.2% | — | Cisco Unified CallmanagerCisco Unified Communications ManagerCisco IOS | 26/9/2008 | 16/6/2026 | Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug… | |
| Modificada | Alta (7.1) | 3.5% | — | Cisco Unified CallmanagerCisco Unified Communications ManagerCisco IOS | 26/9/2008 | 16/6/2026 | Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug… | |
| Modificada | Alta (7.8) | 1.2% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 16/5/2008 | 16/6/2026 | The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network traffic, aka Bug ID CSCsk46770. | |
| Modificada | Media (6.8) | 7.7% | 💥 Exploit | Activision Call OF Duty 4 | 7/5/2008 | 16/6/2026 | Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers a memcpy with a negative value. | |
| Modificada | Media (6.5) | 1.9% | 💥 Exploit | Cisco Unified CallmanagerCisco Unified Communications Manager | 14/2/2008 | 16/6/2026 | SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages. | |
| Modificada | Alta (10) | 57% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 17/1/2008 | 16/6/2026 | Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code… | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 18/10/2007 | 16/6/2026 | Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource exhaustion, aka CSCsi75822. | |
| Modificada | Alta (10) | 5.5% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 18/10/2007 | 16/6/2026 | Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and Unified CallManager 5.0, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors involving the processing of filenames,… | |
| Modificada | Media (5) | 1.6% | — | Cisco Call Manager | 16/10/2007 | 16/6/2026 | Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka "toll fraud and authentication forward attack"). | |
| Modificada | Alta (9.3) | 6.5% | — | Callisto Photoparade Player | 14/9/2007 | 16/6/2026 | Buffer overflow in the PhPInfo ActiveX control in PhPCtrl.dll in Callisto PhotoParade Player allows remote attackers to execute arbitrary code via the FileVersionof property. | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Unified Communications ManagerCisco Call Manager | 31/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin… | |
| Modificada | Alta (9.3) | 4.3% | 💥 Exploit | Cisco Unified Communications ManagerCisco Call Manager | 31/8/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka… | |
| Modificada | Alta (10) | 8.9% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 15/7/2007 | 16/6/2026 | Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 9.6% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 15/7/2007 | 16/6/2026 | Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow. |