Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)13%💥 ExploitAnshul Sharma Category-grid-view-gallery16/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
ModificadaAlta (7.5)2.1%💥 ExploitScript-shop24 LM Starmail Paidmail25/8/201016/6/2026
PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
ModificadaAlta (7.5)0.95%💥 ExploitScript-shop24 LM Starmail Paidmail25/8/201016/6/2026
SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaMedia (5)1.8%—Bistudio ArmaBistudio Arma 220/7/200916/6/2026
Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service via a join packet with a final field whose value is (1) 0, which triggers a server crash related to memory allocation, or (2) 1, which triggers CPU/memory consumption and…
ModificadaAlta (10)4.4%—Bistudio ArmaBistudio Arma 220/7/200916/6/2026
Format string vulnerability in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) nickname and (2) datafile fields in a join request,…
ModificadaMedia (5)1.5%—Bistudio ArmaBistudio Arma 220/7/200916/6/2026
Integer underflow in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) via a VoIP over Network (VON) packet to port 2305 with a negative packet_size value, which triggers a buffer over-read.
ModificadaAlta (7.5)2.1%💥 ExploitArmassa Ard-9808 SoftwareArmassa Ard-98082/7/200916/6/2026
The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing usernames and passwords via a direct request for dvr.ini.
ModificadaAlta (7.8)2.3%💥 ExploitArmassa Ard-9808 SoftwareArmassa Ard-98082/7/200916/6/2026
The ARD-9808 DVR card security camera allows remote attackers to cause a denial of service via a long URI composed of //.\ (slash slash dot backslash) sequences.
ModificadaMedia (6.5)0.93%—Drupal User Karma Module25/2/200916/6/2026
Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value.
ModificadaMedia (4.3)1.1%—Drupal User Karma Module25/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.
ModificadaAlta (7.5)1.00%💥 ExploitFizzmedia Negativekarma Fizzmedia30/7/200816/6/2026
SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
ModificadaMedia (5)2.7%💥 ExploitNetart Media Pharmacy System27/6/200716/6/2026
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.
ModificadaAlta (7.5)1.0%💥 ExploitNetart Media Pharmacy System27/6/200716/6/2026
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.
ModificadaAlta (7.5)2.7%💥 ExploitBarman18/12/200616/6/2026
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter.
ModificadaAlta (10)4.2%—Oracle Pharmaceutical18/10/200616/6/2026
Unspecified vulnerability in Oracle Pharmaceutical Applications 4.5.1 has unknown impact and remote authenticated attack vectors, aka Vuln# PHAR01.
ModificadaMedia (5)1.9%—Armagetron Advanced18/7/200616/6/2026
nNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote attackers to cause a denial of service (application crash) via a large owner value, which causes an assert error.
ModificadaAlta (7.8)2.3%—Armagetron Advanced18/7/200616/6/2026
nNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a large number handled by the id_req_handler function.
ModificadaAlta (10)4.6%—Jdedwards Enterpriseone ToolsOneworld ToolsOracle Application ServerOracle Collaboration Suite+820/4/200616/6/2026
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
ModificadaAlta (7.5)4.9%💥 ExploitMarmaraweb E-commerce16/12/200516/6/2026
PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php.
ModificadaMedia (4.3)1.9%💥 ExploitMarmaraweb E-commerce16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287.
ModificadaMedia (5.3)3.5%💥 ExploitArmagetronad ArmagetronArmagetronad Armagetron Advanced2/5/200516/6/2026
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.
ModificadaMedia (5)3.2%💥 ExploitArmagetronArmagetron Advanced2/5/200516/6/2026
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket.
ModificadaMedia (5)1.3%—ArmagetronArmagetron Advanced2/5/200516/6/2026
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data.
ModificadaAlta (7.5)4.1%—Sharman Networks Kazaa2/7/200316/6/2026
Buffer overflow in FastTrack (FT) network code, as used in Kazaa 2.0.2 and possibly other versions and products, allows remote attackers to execute arbitrary code via a packet containing a large list of supernodes, aka "Packet 0' death."
ModificadaAlta (10)4.0%—Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+1112/3/200116/6/2026
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
Orbitaley — Vulnerabilidades