Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 13% | 💥 Exploit | Anshul Sharma Category-grid-view-gallery | 16/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ID parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Script-shop24 LM Starmail Paidmail | 25/8/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Script-shop24 LM Starmail Paidmail | 25/8/2010 | 16/6/2026 | SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Media (5) | 1.8% | — | Bistudio ArmaBistudio Arma 2 | 20/7/2009 | 16/6/2026 | Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service via a join packet with a final field whose value is (1) 0, which triggers a server crash related to memory allocation, or (2) 1, which triggers CPU/memory consumption and… | |
| Modificada | Alta (10) | 4.4% | — | Bistudio ArmaBistudio Arma 2 | 20/7/2009 | 16/6/2026 | Format string vulnerability in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) nickname and (2) datafile fields in a join request,… | |
| Modificada | Media (5) | 1.5% | — | Bistudio ArmaBistudio Arma 2 | 20/7/2009 | 16/6/2026 | Integer underflow in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) via a VoIP over Network (VON) packet to port 2305 with a negative packet_size value, which triggers a buffer over-read. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Armassa Ard-9808 SoftwareArmassa Ard-9808 | 2/7/2009 | 16/6/2026 | The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing usernames and passwords via a direct request for dvr.ini. | |
| Modificada | Alta (7.8) | 2.3% | 💥 Exploit | Armassa Ard-9808 SoftwareArmassa Ard-9808 | 2/7/2009 | 16/6/2026 | The ARD-9808 DVR card security camera allows remote attackers to cause a denial of service via a long URI composed of //.\ (slash slash dot backslash) sequences. | |
| Modificada | Media (6.5) | 0.93% | — | Drupal User Karma Module | 25/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value. | |
| Modificada | Media (4.3) | 1.1% | — | Drupal User Karma Module | 25/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Fizzmedia Negativekarma Fizzmedia | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Netart Media Pharmacy System | 27/6/2007 | 16/6/2026 | index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Netart Media Pharmacy System | 27/6/2007 | 16/6/2026 | SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Barman | 18/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter. | |
| Modificada | Alta (10) | 4.2% | — | Oracle Pharmaceutical | 18/10/2006 | 16/6/2026 | Unspecified vulnerability in Oracle Pharmaceutical Applications 4.5.1 has unknown impact and remote authenticated attack vectors, aka Vuln# PHAR01. | |
| Modificada | Media (5) | 1.9% | — | Armagetron Advanced | 18/7/2006 | 16/6/2026 | nNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote attackers to cause a denial of service (application crash) via a large owner value, which causes an assert error. | |
| Modificada | Alta (7.8) | 2.3% | — | Armagetron Advanced | 18/7/2006 | 16/6/2026 | nNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a large number handled by the id_req_handler function. | |
| Modificada | Alta (10) | 4.6% | — | Jdedwards Enterpriseone ToolsOneworld ToolsOracle Application ServerOracle Collaboration Suite+8 | 20/4/2006 | 16/6/2026 | Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Marmaraweb E-commerce | 16/12/2005 | 16/6/2026 | PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Marmaraweb E-commerce | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287. | |
| Modificada | Media (5.3) | 3.5% | 💥 Exploit | Armagetronad ArmagetronArmagetronad Armagetron Advanced | 2/5/2005 | 16/6/2026 | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | ArmagetronArmagetron Advanced | 2/5/2005 | 16/6/2026 | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket. | |
| Modificada | Media (5) | 1.3% | — | ArmagetronArmagetron Advanced | 2/5/2005 | 16/6/2026 | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data. | |
| Modificada | Alta (7.5) | 4.1% | — | Sharman Networks Kazaa | 2/7/2003 | 16/6/2026 | Buffer overflow in FastTrack (FT) network code, as used in Kazaa 2.0.2 and possibly other versions and products, allows remote attackers to execute arbitrary code via a packet containing a large list of supernodes, aka "Packet 0' death." | |
| Modificada | Alta (10) | 4.0% | — | Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+11 | 12/3/2001 | 16/6/2026 | Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. |