Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 2.1% | — | Schrack Technik Microcontrol FirmwareSchrack Technik Microcontrol | 20/10/2014 | 17/6/2026 | Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direct request for ZTPUsrDtls.txt. | |
| Modificada | Media (5.4) | 0.27% | — | Pocketmags Inside Crochet | 23/9/2014 | 17/6/2026 | The Inside Crochet (aka com.magazinecloner.insidecrochet) application @7F08017A for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.1% | — | Schrack Technik Microcontrol FirmwareSchrack Technik Microcontrol | 22/8/2014 | 17/6/2026 | The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for the "user" account, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Media (4.3) | 0.98% | — | Schrack Technik Microcontrol FirmwareSchrack Technik Microcontrol | 20/8/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Schrack Technik microControl with firmware 1.7.0 (937) allow remote attackers to inject arbitrary web script or HTML via the position textbox in the configuration menu or other unspecified vectors. | |
| Modificada | Media (4.3) | 2.1% | — | Microcart Project Microcart | 12/8/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Microcart 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or (2) query string to _admin/index.php or (3) first_name, (4) last_name, (5) cc, (6) exp, (7) cvv, (8) address1, (9) address2, (10) city, (11) state, (12) zip, (13)… | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Apphp PHP Microcms | 22/9/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from… | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | Apphp PHP Microcms | 22/9/2010 | 16/6/2026 | Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |
| Modificada | Alta (9.3) | 4.9% | 💥 Exploit | Microchip Mplab IDE | 18/5/2009 | 16/6/2026 | Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Microchip Mplab IDE | 11/5/2009 | 16/6/2026 | Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and possibly other fields. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Philippe Crochat Easysite | 20/2/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Philippe CROCHAT EasySite 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the EASYSITE_BASE parameter to (1) browser.php, (2) image_editor.php and (3) skin_chooser.php in configuration/. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Mycrocms | 18/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in MycroCMS 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the entry_id parameter. | |
| Modificada | Media (6.8) | 2.9% | — | Microchip Data Systems Ziptv FOR C++ BuilderMicrochip Data Systems Ziptv FOR Delphi 7Pentaware Pentasuite-proPentaware Pentazip | 8/9/2006 | 16/6/2026 | Heap-based buffer overflow in the TZipTV component in (1) ZipTV for Delphi 7 2006.1.26 and for C++ Builder 2006-1.16, (2) PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221, and possibly other products, allows user-assisted attackers to execute arbitrary code via an ARJ archive with a long header. NOTE: the ACE archive… | |
| Modificada | Alta (7.5) | 1.6% | — | Compaq Microcom 6000 Firmware | 3/6/1998 | 16/6/2026 | Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack. | |
| Modificada | Media (5) | 1.3% | — | Compaq Microcom Microcom 6000 Access Integrator | 3/6/1998 | 16/6/2026 | Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password. |