Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
253 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.9) | 0.34% | — | Beijerelectronics Beijer ADPBeijerelectronics H-designer | 28/1/2013 | 16/6/2026 | Buffer overflow in Beijer ADP 6.5.0-180_R1967 and 6.5.1-186_R2942, and H-Designer 6.5.0 B180_R1967, allows local users to gain privileges by inserting a long string into a DLL file. | |
| Modificada | Media (5) | 1.3% | — | Anelectron Advanced Electron Forum | 23/9/2011 | 16/6/2026 | Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by languages/english/deletetopic_lang.php. | |
| Modificada | Alta (9.3) | 3.1% | — | Hitachi Ucosminexus/opentp1 WEB WEB Front-endsetHitachi Ucosminexus Application ServerHitachi Ucosminexus ClientHitachi Ucosminexus Collaboration+21 | 21/4/2010 | 16/6/2026 | Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF… | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Hirschelectronics Velocity Security Management System | 26/8/2009 | 16/6/2026 | Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Media (4.3) | 1.3% | — | Anelectron Advanced Electron Forum | 20/7/2009 | 16/6/2026 | Directory traversal vulnerability in Advanced Electron Forum (AEF) 1.x allows remote attackers to determine the existence of arbitrary files via the avatargalfile parameter when changing an avatar, which leaks the existence of the file in an error message. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Media (6.8) | 0.99% | — | Anelectron Advanced Electron Forum | 20/7/2009 | 16/6/2026 | SQL injection vulnerability in Advanced Electron Forum (AEF) 1.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the filename in an uploaded attachment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (9.3) | 4.7% | 💥 Exploit | National Instruments Electronics Workbench | 9/12/2008 | 16/6/2026 | Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .ewb file. | |
| Modificada | Alta (10) | 4.6% | 💥 Exploit | Anelectron Advanced Electron Forum | 14/11/2008 | 16/6/2026 | Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Philips Electronics Voip841 Dect Phone | 1/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page. | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | Philips Electronics Voip841 Dect Phone | 1/11/2008 | 16/6/2026 | Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a GET request. NOTE: this can be leveraged with CVE-2008-4874 for unauthenticated access to sensitive files… | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Philips Electronics Voip841 Dect Phone | 1/11/2008 | 16/6/2026 | The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as its password, which makes it easier for remote attackers to obtain access. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Anelectron Advanced Electron Forum | 27/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php. | |
| Modificada | Alta (7.8) | 1.6% | — | LG Electronics LG Mobile Handset | 18/10/2007 | 16/6/2026 | Integer overflow in the LG Mobile handset allows remote attackers to cause a denial of service (reboot) via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier… | |
| Modificada | Media (6.8) | 31% | 💥 Exploit | Electronic Arts Snoopyctrl | 9/10/2007 | 16/6/2026 | Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters. | |
| Modificada | Media (4.4) | 0.28% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+3 | 28/8/2007 | 16/6/2026 | Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges. | |
| Modificada | Media (4.6) | 0.31% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+3 | 28/8/2007 | 16/6/2026 | Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges. | |
| Modificada | Media (4.9) | 1.0% | — | Hitachi Cosminexus Application ServerHitachi Cosminexus Collaboration PortalHitachi Cosminexus DeveloperHitachi Cosminexus ERP Integrator+10 | 1/8/2007 | 16/6/2026 | The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's… | |
| Modificada | Media (5) | 1.2% | — | Hitachi Cosminexus Component ContainerHitachi Electronic Form WorkflowHitachi Ucosminexus Application ServerHitachi Ucosminexus Developer+3 | 3/4/2007 | 16/6/2026 | Unspecified vulnerability in Hitachi Cosminexus Component Container 07-00 through 07-00-10, and 07-10 through 07-10-03, as used in uCosminexus Application Server Enterprise and Standard; uCosminexus Service Platform; uCosminexus Developer Standard and Professional; uCosminexus Service Architect; Electronic Form… | |
| Modificada | Baja (2.9) | 0.61% | — | LG Electronics Chocolate Kg800 | 26/1/2007 | 16/6/2026 | The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push. | |
| Modificada | Alta (7.8) | 2.0% | — | Electronic Arts Nascar Racing | 6/7/2006 | 16/6/2026 | Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded due to use of the FIONREAD asynchronous socket. | |
| Modificada | Media (5) | 1.6% | — | LG Electronics LG Mobile Phone | 2/5/2005 | 16/6/2026 | LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI file. | |
| Modificada | Media (5.1) | 4.3% | 💥 Exploit | Electronic Arts Need FOR Speed HOT Pursuit 2 | 31/12/2004 | 16/6/2026 | Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands. | |
| Modificada | Alta (7.5) | 62% | 💥 Exploit | Electronic Arts Medal OF Honor Allied Assault | 27/7/2004 | 16/6/2026 | Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such as (1) the getinfo query, (2) the connect packet, and other… | |
| Modificada | Alta (7.5) | 4.5% | 💥 Exploit | Electronic Arts Battlefield 1942 | 31/12/2003 | 16/6/2026 | Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password. | |
| Modificada | Media (5) | 6.6% | 💥 Exploit | Nokia Electronic Documentation | 6/10/2003 | 16/6/2026 | Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot). |