Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 2.6% | — | Mevin Basic PHP Events Lister | 11/9/2009 | 16/6/2026 | Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mevin Basic-php-events-lister | 13/3/2009 | 16/6/2026 | SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Acid Analysis Console FOR Intrusion DatabasesSecureideas Basic Analysis AND Security Engine | 18/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to inject arbitrary web… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | I-rater Basic | 2/2/2009 | 16/6/2026 | SQL injection vulnerability in messages.php in I-Rater Basic allows remote attackers to execute arbitrary SQL commands via the idp parameter. | |
| Modificada | Alta (8.5) | 21% | — | Microsoft Office FrontpageMicrosoft ProjectMicrosoft Visual BasicMicrosoft Visual Foxpro+1 | 10/12/2008 | 16/6/2026 | The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document,… | |
| Modificada | Alta (9.3) | 54% | 💥 Exploit | Microsoft Office FrontpageMicrosoft ProjectMicrosoft Visual BasicMicrosoft Visual Foxpro+1 | 10/12/2008 | 16/6/2026 | Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute… | |
| Modificada | Alta (8.5) | 22% | — | Microsoft Office FrontpageMicrosoft ProjectMicrosoft Visual BasicMicrosoft Visual Foxpro+1 | 10/12/2008 | 16/6/2026 | Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to… | |
| Modificada | Alta (8.5) | 21% | — | Microsoft Office FrontpageMicrosoft ProjectMicrosoft Visual BasicMicrosoft Visual Foxpro+1 | 10/12/2008 | 16/6/2026 | The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML… | |
| Modificada | Alta (8.5) | 21% | — | Microsoft Office FrontpageMicrosoft ProjectMicrosoft Visual BasicMicrosoft Visual Foxpro+1 | 10/12/2008 | 16/6/2026 | The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state,"… | |
| Modificada | Alta (7.5) | 1.0% | — | Calendarix Basic | 26/11/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Calendarix Basic 0.8.20071118 allow remote attackers to execute arbitrary SQL commands via (1) the catsearch parameter to cal_search.php or (2) the catview parameter to cal_cat.php. NOTE: vector 1 might overlap CVE-2007-3183.3, and vector 2 might overlap CVE-2005-1865.2. | |
| Modificada | Alta (9.3) | 56% | 💥 Exploit | Microsoft Visual BasicMicrosoft Visual FoxproMicrosoft Visual StudioMicrosoft Visual Studio .net | 18/8/2008 | 16/6/2026 | Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary… | |
| Modificada | Alta (9.3) | 25% | 💥 Exploit | Microsoft Visual Basic Enterprise Edition | 2/7/2008 | 16/6/2026 | Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might allow remote attackers to execute arbitrary code via a long lpstrLinkPath argument to the fCreateShellLink function. | |
| Modificada | Alta (7.5) | 23% | 💥 Exploit | Basic-cms | 20/6/2008 | 16/6/2026 | SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands via the page_id parameter. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Cyan Soft Cyanprintip BasicCyan Soft Cyanprintip Easy OPICyan Soft Cyanprintip ProfessionalCyan Soft Cyanprintip Standard+2 | 13/2/2008 | 16/6/2026 | Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; might allow remote attackers to execute… | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Cyan Soft Cyanprintip BasicCyan Soft Cyanprintip Easy OPICyan Soft Cyanprintip ProfessionalCyan Soft Cyanprintip Standard+2 | 13/2/2008 | 16/6/2026 | The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; allows remote attackers to cause a denial of service (daemon crash) via a connection that begins with (1) a "Send… | |
| Modificada | Alta (9.3) | 6.9% | 💥 Exploit | Cowon America Jetaudio Basic | 13/2/2008 | 16/6/2026 | Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute arbitrary code via a long URL in a .asx file, a different vulnerability than CVE-2007-5487. | |
| Modificada | Alta (10) | 43% | — | Microsoft OfficeMicrosoft Visual Basic | 12/2/2008 | 16/6/2026 | Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request. | |
| Modificada | Alta (9.3) | 30% | 💥 Exploit | Microsoft Visual Basic | 23/1/2008 | 16/6/2026 | Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line. | |
| Modificada | Media (4.3) | 1.3% | — | Secureideas Basic Analysis AND Security Engine | 29/11/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in base_qry_main.php in Base Analysis and Security Engine (BASE) before 1.3.9 allow remote attackers to inject arbitrary web script or HTML via the (1) sig[0] and (2) sig[1] parameters. | |
| Modificada | Media (6.8) | 1.1% | — | Phpbasic | 29/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in includes.php in phpBasic allows remote attackers to execute arbitrary PHP code via a URL in the root parameter, possibly related to the Music module. | |
| Modificada | Alta (7.5) | 1.5% | — | Phpbasic | 24/10/2007 | 16/6/2026 | SQL injection vulnerability in the Music module in phpBasic allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to the default URI. | |
| Modificada | Alta (7.5) | 1.8% | — | Secureideas Basic Analysis AND Security Engine | 18/10/2007 | 16/6/2026 | Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication via (1) base_main.php, (2) base_qry_alert.php, and possibly other vectors. | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft Visual Basic | 10/9/2007 | 16/6/2026 | Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Visual Basic project (vbp) file containing a long Reference line, related to VBP_Open and OLE. NOTE: there are limited usage scenarios under which this would be a… | |
| Modificada | Alta (9.3) | 35% | — | Microsoft OfficeMicrosoft Visual Basic | 14/8/2007 | 16/6/2026 | Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer… | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Microsoft Visual Basic | 30/5/2007 | 16/6/2026 | Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field. |