Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.98% | — | Innovasys Dockstudioxp | 10/7/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in the Innovasys DockStudioXP InnovaDSXP2.OCX ActiveX Control have unspecified attack vectors and impact, including a denial of service via "improper use" of the SaveToFile function. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Innovate Portal | 21/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Innovate Portal 2.0 allows remote attackers to inject arbitrary web script or HTML via the content parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Tutti Nova | 21/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Tutti Nova | 21/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to (1) include/novalib/class.novaAdmin.mysql.php and (2) novalib/class.novaRead.mysql.php. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Media (4.9) | 0.33% | — | Enova X-wall Asic | 30/3/2006 | 16/6/2026 | The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware token, or by sniffing the Microwire bus. | |
| Modificada | Media (5) | 1.3% | — | Innovative CMS | 14/12/2005 | 16/6/2026 | setting.php in Innovative CMS (ICMS, formerly Imoel-CMS) contains username and password information in cleartext, which might allow attackers to obtain this information via a direct request to setting.php. NOTE: on a properly configured web server, it would be expected that a .php file would be processed before… | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Innovateware Sights N Sounds Streaming Media Server | 13/12/2005 | 16/6/2026 | Buffer overflow in MediaServerList.exe in Sights 'n Sounds Streaming Media Server 2.0.3.a allows remote attackers to cause a denial of service (application crash) via a long query string. | |
| Modificada | Alta (7.5) | 1.7% | — | Bosanova Launcher400IBM Client AccessMochasoft Tn5250Powerterm Interconnect | 2/5/2005 | 16/6/2026 | AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as… | |
| Modificada | Alta (10) | 1.7% | — | Tutti Nova | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Tutti Nova 0.10 through 0.12 (Beta) and 0.9.4, when register_globals is enabled, has unknown impact and attack vectors. |