Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

253 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.9)0.34%—Beijerelectronics Beijer ADPBeijerelectronics H-designer28/1/201316/6/2026
Buffer overflow in Beijer ADP 6.5.0-180_R1967 and 6.5.1-186_R2942, and H-Designer 6.5.0 B180_R1967, allows local users to gain privileges by inserting a long string into a DLL file.
ModificadaMedia (5)1.3%—Anelectron Advanced Electron Forum23/9/201116/6/2026
Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by languages/english/deletetopic_lang.php.
ModificadaAlta (9.3)3.1%—Hitachi Ucosminexus/opentp1 WEB WEB Front-endsetHitachi Ucosminexus Application ServerHitachi Ucosminexus ClientHitachi Ucosminexus Collaboration+2121/4/201016/6/2026
Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF…
ModificadaMedia (5)2.8%💥 ExploitHirschelectronics Velocity Security Management System26/8/200916/6/2026
Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
ModificadaMedia (4.3)1.3%—Anelectron Advanced Electron Forum20/7/200916/6/2026
Directory traversal vulnerability in Advanced Electron Forum (AEF) 1.x allows remote attackers to determine the existence of arbitrary files via the avatargalfile parameter when changing an avatar, which leaks the existence of the file in an error message. NOTE: the provenance of this information is unknown; the…
ModificadaMedia (6.8)0.99%—Anelectron Advanced Electron Forum20/7/200916/6/2026
SQL injection vulnerability in Advanced Electron Forum (AEF) 1.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the filename in an uploaded attachment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (9.3)4.7%💥 ExploitNational Instruments Electronics Workbench9/12/200816/6/2026
Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .ewb file.
ModificadaAlta (10)4.6%💥 ExploitAnelectron Advanced Electron Forum14/11/200816/6/2026
Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.
ModificadaMedia (4.3)1.8%💥 ExploitPhilips Electronics Voip841 Dect Phone1/11/200816/6/2026
Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page.
ModificadaMedia (6.8)3.1%💥 ExploitPhilips Electronics Voip841 Dect Phone1/11/200816/6/2026
Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a GET request. NOTE: this can be leveraged with CVE-2008-4874 for unauthenticated access to sensitive files…
ModificadaMedia (5)3.5%💥 ExploitPhilips Electronics Voip841 Dect Phone1/11/200816/6/2026
The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as its password, which makes it easier for remote attackers to obtain access.
ModificadaMedia (4.3)1.5%💥 ExploitAnelectron Advanced Electron Forum27/4/200816/6/2026
Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php.
ModificadaAlta (7.8)1.6%—LG Electronics LG Mobile Handset18/10/200716/6/2026
Integer overflow in the LG Mobile handset allows remote attackers to cause a denial of service (reboot) via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier…
ModificadaMedia (6.8)31%💥 ExploitElectronic Arts Snoopyctrl9/10/200716/6/2026
Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters.
ModificadaMedia (4.4)0.28%—Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+328/8/200716/6/2026
Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.
ModificadaMedia (4.6)0.31%—Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+328/8/200716/6/2026
Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges.
ModificadaMedia (4.9)1.0%—Hitachi Cosminexus Application ServerHitachi Cosminexus Collaboration PortalHitachi Cosminexus DeveloperHitachi Cosminexus ERP Integrator+101/8/200716/6/2026
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's…
ModificadaMedia (5)1.2%—Hitachi Cosminexus Component ContainerHitachi Electronic Form WorkflowHitachi Ucosminexus Application ServerHitachi Ucosminexus Developer+33/4/200716/6/2026
Unspecified vulnerability in Hitachi Cosminexus Component Container 07-00 through 07-00-10, and 07-10 through 07-10-03, as used in uCosminexus Application Server Enterprise and Standard; uCosminexus Service Platform; uCosminexus Developer Standard and Professional; uCosminexus Service Architect; Electronic Form…
ModificadaBaja (2.9)0.61%—LG Electronics Chocolate Kg80026/1/200716/6/2026
The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.
ModificadaAlta (7.8)2.0%—Electronic Arts Nascar Racing6/7/200616/6/2026
Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded due to use of the FIONREAD asynchronous socket.
ModificadaMedia (5)1.6%—LG Electronics LG Mobile Phone2/5/200516/6/2026
LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI file.
ModificadaMedia (5.1)4.3%💥 ExploitElectronic Arts Need FOR Speed HOT Pursuit 231/12/200416/6/2026
Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.
ModificadaAlta (7.5)62%💥 ExploitElectronic Arts Medal OF Honor Allied Assault27/7/200416/6/2026
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such as (1) the getinfo query, (2) the connect packet, and other…
ModificadaAlta (7.5)4.5%💥 ExploitElectronic Arts Battlefield 194231/12/200316/6/2026
Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.
ModificadaMedia (5)6.6%💥 ExploitNokia Electronic Documentation6/10/200316/6/2026
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).
Orbitaley — Vulnerabilidades