Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | HP Envy 100 D410HP Photosmart B110HP Photosmart D110HP Photosmart Plus B210+3 | 15/4/2011 | 16/6/2026 | The webscan component in the Embedded Web Server (EWS) on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to read documents on the scan surface via unspecified vectors. | |
| Modificada | Alta (9.3) | 14% | 💥 Exploit | Adobe Photoshop | 26/8/2010 | 16/6/2026 | Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop.… | |
| Modificada | Alta (9.3) | 20% | 💥 Exploit | Adobe Photoshop CS4 | 27/5/2010 | 16/6/2026 | Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2) .ABR, or (3) .GRD file. | |
| Modificada | Alta (9.3) | 4.6% | — | Adobe Photoshop CS4 | 5/5/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in Adobe Photoshop CS4 11.x before 11.0.1 allow user-assisted remote attackers to execute arbitrary code via a crafted TIFF file. | |
| Modificada | Alta (7.8) | 2.0% | 💥 Exploit | Adobe Photoshop Elements | 30/9/2009 | 16/6/2026 | Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Ktools Photostore | 7/4/2009 | 16/6/2026 | SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Ktools Photostore | 7/4/2009 | 16/6/2026 | SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter to about_us.php. NOTE: this might be the same issue as CVE-2008-6647. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Ktools Photostore | 7/4/2009 | 16/6/2026 | SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL commands via the gid parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Kaphotoservice | 8/8/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice allow remote attackers to inject arbitrary web script or HTML via the (1) filename parameter to search.asp and the (2) page parameter to order.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (6.8) | 3.1% | — | Photostockplus Uploader Tool | 20/5/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the PhotoStockPlus Uploader Tool ActiveX control (PSPUploader.ocx) allow remote attackers to execute arbitrary code via unspecified initialization parameters. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Thomas Voecking Internet Photoshow | 18/5/2008 | 16/6/2026 | admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true. | |
| Modificada | Alta (9.3) | 20% | 💥 Exploit | Adobe Photoshop | 23/4/2008 | 16/6/2026 | Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Kaphotoservice | 20/3/2008 | 16/6/2026 | SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via the albumid parameter. | |
| Modificada | Alta (9.3) | 41% | 💥 Exploit | Adobe GoliveAdobe IllustratorAdobe PhotoshopAdobe Photoshop Elements | 30/4/2007 | 16/6/2026 | Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file. | |
| Modificada | Alta (9.3) | 32% | 💥 Exploit | Adobe GoliveAdobe IllustratorAdobe Photoshop | 25/4/2007 | 16/6/2026 | Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file. | |
| Modificada | Media (5) | 1.5% | — | Photostand | 26/2/2007 | 16/6/2026 | Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Photostand | 26/2/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message ("comment") or (2) name field, or the (3) q parameter in a search action in index.php. | |
| Modificada | Media (4.1) | 0.74% | 💥 Exploit | PML Driver Hpz12HP Color Laserjet 4650HP Officejet 4100HP Officejet 5100+17 | 10/1/2007 | 16/6/2026 | The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023. | |
| Modificada | Alta (7.8) | 1.6% | — | Gphotos | 4/12/2006 | 16/6/2026 | index.php in GPhotos 1.5 allows remote attackers to obtain sensitive information via an invalid rep parameter, which reveals the full path in an error message. | |
| Modificada | Alta (7.5) | 1.5% | — | Myphotos | 29/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in MyPhotos 0.1.3b beta allows remote attackers to execute arbitrary PHP code via the includesdir parameter. NOTE: this issue is disputed by CVE on 20060927, since the includesdir is defined before being used when the product is installed according to the provided… | |
| Modificada | Media (5.1) | 2.1% | 💥 Exploit | Ktools.net Photostore | 28/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Enthrallweb Ephotos | 15/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp, and the (3) SUB_ID parameter in (d) subLevel2.asp. | |
| Modificada | Media (4.3) | 4.3% | 💥 Exploit | Kaphotoservice | 12/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) New Category (newcategory) or (2) apage parameter to (a) edtalbum.asp, or the (3) cat or (4) albumid parameter to (b) album.asp. | |
| Modificada | Media (5) | 4.2% | 💥 Exploit | Gphotos | 16/5/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in GPhotos 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rep parameter. | |
| Modificada | Media (5.8) | 2.8% | 💥 Exploit | Gphotos | 16/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) rep parameter to (a) index.php or (b) diapo.php or (2) image parameter to (c) affich.php. NOTE: item 1a might be resultant from directory traversal. |