Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)12%💥 ExploitPro-face Pro-server EXPro-face Wingp PC Runtime25/6/201216/6/2026
Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow.
ModificadaMedia (5)11%💥 ExploitPro-face Pro-server EXPro-face Wingp PC Runtime25/6/201216/6/2026
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (out-of-bounds read operation) via a crafted packet that triggers a certain Find Node check attempt.
ModificadaAlta (7.5)1.3%—Nadine Schwingler KE Questionnaire9/10/201116/6/2026
SQL injection vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.2%—Nadine Schwingler KE Questionnaire9/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)2.0%—Wftpserver Wing FTP Server24/6/201016/6/2026
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.
ModificadaAlta (9.3)25%💥 ExploitAwingsoft Awakening Winds3d Viewer Plugin7/5/201016/6/2026
The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneURL property value with a URL for a .exe file.
ModificadaAlta (7.5)3.1%💥 ExploitPhppower Swinger Club Portal26/3/201016/6/2026
PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary PHP code via a URL in the go parameter.
ModificadaAlta (7.5)0.99%💥 ExploitPhppower Swinger Club Portal26/3/201016/6/2026
SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action.
ModificadaAlta (9.3)32%💥 ExploitAwingsoft Awakening Winds3d PlayerAwingsoft Awakening Winds3d Viewer7/1/201016/6/2026
Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long SceneUrl property value, a…
ModificadaMedia (4.3)4.5%💥 ExploitIntertwingly PlanetIntertwingly Planet Venus18/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed.
ModificadaAlta (9.3)5.1%💥 ExploitAwingsoft Awakening Winds3d Viewer Plugin10/7/200916/6/2026
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.
ModificadaMedia (5.4)2.4%—Qbik Wingate4/3/200916/6/2026
Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page…
ModificadaMedia (6.5)4.5%💥 ExploitQbik Wingate12/8/200816/6/2026
Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)2.1%—IrssiKristof Korwisi IxmmsaMikachu L33t Xmms Music Showing ScriptRicardo Mesquita Mpg123+318/8/200716/6/2026
Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) a2x 0.0.1, (5) Another xmms-info script 1.0, (6) XChat-XMMS 0.8.1, and other unspecified scripts for XChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in…
ModificadaMedia (5)2.0%—Qbik Wingate14/8/200716/6/2026
Format string vulnerability in the SMTP server component in Qbik WinGate 5.x and 6.x before 6.2.2 allows remote attackers to cause a denial of service (service crash) via format string specifiers in certain unexpected commands, which trigger a crash during error logging.
ModificadaMedia (5)1.4%—Weekly Drawing Contest22/3/200716/6/2026
Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the order parameter. NOTE: another researcher disputes this vulnerability, noting that the order variable is not used in any context that allows opening files
ModificadaAlta (7.5)1.3%—Weekly Drawing Contest22/3/200716/6/2026
admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request.
ModificadaAlta (7.5)1.0%—Weekly Drawing Contest22/3/200716/6/2026
SQL injection vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to execute arbitrary SQL commands via the order parameter.
ModificadaMedia (5)1.8%—Qbik Wingate28/11/200616/6/2026
Qbik WinGate 6.1.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a DNS request with a self-referencing compressed name pointer, which triggers an infinite loop.
ModificadaBaja (2.6)1.8%💥 ExploitWinged Gallery13/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
ModificadaMedia (5.5)1.4%—Qbik Wingate10/7/200616/6/2026
Directory traversal vulnerability in the IMAP server in WinGate 6.1.2.1094 and 6.1.3.1096, and possibly other versions before 6.1.4 Build 1099, allows remote authenticated users to read email of other users, or perform unauthorized operations on directories, via the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5)…
ModificadaMedia (5)2.3%—JED Wing CHM LIB23/6/200616/6/2026
Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attackers to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename.
ModificadaAlta (7.5)71%💥 ExploitQbik Wingate9/6/200616/6/2026
Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL HTTP request.
ModificadaMedia (4.3)1.3%—Wingnut Easygallery21/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in EasyGallery.php in Wingnut EasyGallery allows remote attackers to inject arbitrary web script or HTML via the ordner parameter.
ModificadaAlta (10)2.2%—JED Wing CHM LIB16/11/200516/6/2026
Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.