Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.9)0.78%💥 ExploitAvast Antivirus HomeAvast Antivirus Professional1/10/200916/6/2026
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than…
ModificadaAlta (7.2)0.95%💥 ExploitAvast Antivirus HomeAvast Antivirus Professional1/10/200916/6/2026
Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.
ModificadaAlta (7.2)0.65%—Avira AntivirAvira Antivir PersonalAvira Antivir ProfessionalAvira Antivir Security Suite13/8/200916/6/2026
Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE allows local users to execute arbitrary code via a crafted IOCTL request that overwrites a kernel pointer.
ModificadaAlta (9.3)3.6%—RIM Blackberry Enterprise ServerRIM Blackberry Professional Software30/7/200916/6/2026
Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.6 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or…
ModificadaAlta (9.3)5.0%—RIM Blackberry Enterprise ServerRIM Blackberry Professional Software28/7/200916/6/2026
Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 5.0 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or…
ModificadaAlta (7.5)0.97%💥 ExploitMxmania Calendar MX Professional2/3/200916/6/2026
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (9.3)4.9%—Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite21/1/200916/6/2026
The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to…
ModificadaAlta (9.3)5.5%—Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite20/1/200916/6/2026
Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via…
ModificadaMedia (5)7.4%💥 ExploitDotnetindex Professional Download Assistant15/12/200816/6/2026
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb.
ModificadaAlta (7.5)2.4%💥 ExploitDotnetindex Professional Download Assistant15/12/200816/6/2026
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.00%💥 Exploit1ST News 4 Professional4/11/200816/6/2026
SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.1%—Uniwin Ecart Professional27/10/200816/6/2026
Multiple SQL injection vulnerabilities in Uniwin eCart Professional 2.0.17 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) search.asp and (2) cartUtil.asp.
ModificadaMedia (4.3)1.0%—Uniwin Ecart Professional27/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in emailFriend.asp in Uniwin eCart Professional 2.0.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)17%—Microsoft AccessMicrosoft ExcelMicrosoft FrontpageMicrosoft Groove+137/7/200816/6/2026
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times…
ModificadaMedia (6.8)0.71%💥 ExploitAvast Antivirus HomeAvast Antivirus Professional2/4/200816/6/2026
aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain privileges via certain IOCTL requests.
ModificadaAlta (9)7.1%💥 ExploitMailenable EnterpriseMailenable Professional10/3/200816/6/2026
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote authenticated attackers to execute arbitrary code via long arguments to the (1) FETCH, (2) EXAMINE, and (3) UNSUBSCRIBE commands.
ModificadaAlta (7.8)4.0%💥 ExploitMailenable EnterpriseMailenable ProfessionalMailenable Standard10/3/200816/6/2026
Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edition 3.x and earlier allow remote attackers to cause a denial of service (crash) via crafted (1) EXPN or (2) VRFY commands.
ModificadaAlta (9)8.3%💥 ExploitMailenable EnterpriseMailenable Professional10/3/200816/6/2026
The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial of service (crash) via (1) SEARCH and (2) APPEND commands without required arguments, which triggers a NULL pointer dereference.
ModificadaAlta (7.5)4.9%💥 ExploitCyan Soft Cyanprintip BasicCyan Soft Cyanprintip Easy OPICyan Soft Cyanprintip ProfessionalCyan Soft Cyanprintip Standard+213/2/200816/6/2026
Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; might allow remote attackers to execute…
ModificadaMedia (5)3.2%💥 ExploitCyan Soft Cyanprintip BasicCyan Soft Cyanprintip Easy OPICyan Soft Cyanprintip ProfessionalCyan Soft Cyanprintip Standard+213/2/200816/6/2026
The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; allows remote attackers to cause a denial of service (daemon crash) via a connection that begins with (1) a "Send…
ModificadaMedia (4.3)0.84%—Uniwin Ecart Professional4/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified other components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (10)5.2%💥 ExploitRaiden Professional Servers Raidenhttpd20/12/200716/6/2026
Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ulang parameter.
ModificadaMedia (6.8)1.3%—Avast Antivirus HomeAvast Antivirus Professional7/12/200716/6/2026
Unspecified vulnerability in avast! 4 Home and Professional Editions before 4.7.1098 allows remote attackers to have an unknown impact via a crafted TAR archive.
ModificadaMedia (6.8)1.1%—Swsoft Confixx Professional20/11/200716/6/2026
PHP remote file inclusion vulnerability in fehler.inc.php in SWSoft Confixx Professional 3.2.1 allows remote attackers to execute arbitrary PHP code via a URL in an unspecified parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)0.78%—Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+105/11/200716/6/2026
Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature.
Orbitaley — Vulnerabilidades