Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 12% | 💥 Exploit | Pro-face Pro-server EXPro-face Wingp PC Runtime | 25/6/2012 | 16/6/2026 | Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Pro-face Pro-server EXPro-face Wingp PC Runtime | 25/6/2012 | 16/6/2026 | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (out-of-bounds read operation) via a crafted packet that triggers a certain Find Node check attempt. | |
| Modificada | Alta (7.5) | 1.3% | — | Nadine Schwingler KE Questionnaire | 9/10/2011 | 16/6/2026 | SQL injection vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Nadine Schwingler KE Questionnaire | 9/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Wftpserver Wing FTP Server | 24/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request. | |
| Modificada | Alta (9.3) | 25% | 💥 Exploit | Awingsoft Awakening Winds3d Viewer Plugin | 7/5/2010 | 16/6/2026 | The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneURL property value with a URL for a .exe file. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Phppower Swinger Club Portal | 26/3/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary PHP code via a URL in the go parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Phppower Swinger Club Portal | 26/3/2010 | 16/6/2026 | SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action. | |
| Modificada | Alta (9.3) | 32% | 💥 Exploit | Awingsoft Awakening Winds3d PlayerAwingsoft Awakening Winds3d Viewer | 7/1/2010 | 16/6/2026 | Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long SceneUrl property value, a… | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Intertwingly PlanetIntertwingly Planet Venus | 18/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed. | |
| Modificada | Alta (9.3) | 5.1% | 💥 Exploit | Awingsoft Awakening Winds3d Viewer Plugin | 10/7/2009 | 16/6/2026 | Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method. | |
| Modificada | Media (5.4) | 2.4% | — | Qbik Wingate | 4/3/2009 | 16/6/2026 | Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page… | |
| Modificada | Media (6.5) | 4.5% | 💥 Exploit | Qbik Wingate | 12/8/2008 | 16/6/2026 | Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 2.1% | — | IrssiKristof Korwisi IxmmsaMikachu L33t Xmms Music Showing ScriptRicardo Mesquita Mpg123+3 | 18/8/2007 | 16/6/2026 | Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) a2x 0.0.1, (5) Another xmms-info script 1.0, (6) XChat-XMMS 0.8.1, and other unspecified scripts for XChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in… | |
| Modificada | Media (5) | 2.0% | — | Qbik Wingate | 14/8/2007 | 16/6/2026 | Format string vulnerability in the SMTP server component in Qbik WinGate 5.x and 6.x before 6.2.2 allows remote attackers to cause a denial of service (service crash) via format string specifiers in certain unexpected commands, which trigger a crash during error logging. | |
| Modificada | Media (5) | 1.4% | — | Weekly Drawing Contest | 22/3/2007 | 16/6/2026 | Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the order parameter. NOTE: another researcher disputes this vulnerability, noting that the order variable is not used in any context that allows opening files | |
| Modificada | Alta (7.5) | 1.3% | — | Weekly Drawing Contest | 22/3/2007 | 16/6/2026 | admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request. | |
| Modificada | Alta (7.5) | 1.0% | — | Weekly Drawing Contest | 22/3/2007 | 16/6/2026 | SQL injection vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to execute arbitrary SQL commands via the order parameter. | |
| Modificada | Media (5) | 1.8% | — | Qbik Wingate | 28/11/2006 | 16/6/2026 | Qbik WinGate 6.1.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a DNS request with a self-referencing compressed name pointer, which triggers an infinite loop. | |
| Modificada | Baja (2.6) | 1.8% | 💥 Exploit | Winged Gallery | 13/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter. | |
| Modificada | Media (5.5) | 1.4% | — | Qbik Wingate | 10/7/2006 | 16/6/2026 | Directory traversal vulnerability in the IMAP server in WinGate 6.1.2.1094 and 6.1.3.1096, and possibly other versions before 6.1.4 Build 1099, allows remote authenticated users to read email of other users, or perform unauthorized operations on directories, via the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5)… | |
| Modificada | Media (5) | 2.3% | — | JED Wing CHM LIB | 23/6/2006 | 16/6/2026 | Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attackers to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename. | |
| Modificada | Alta (7.5) | 71% | 💥 Exploit | Qbik Wingate | 9/6/2006 | 16/6/2026 | Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL HTTP request. | |
| Modificada | Media (4.3) | 1.3% | — | Wingnut Easygallery | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EasyGallery.php in Wingnut EasyGallery allows remote attackers to inject arbitrary web script or HTML via the ordner parameter. | |
| Modificada | Alta (10) | 2.2% | — | JED Wing CHM LIB | 16/11/2005 | 16/6/2026 | Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors. |