Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

307 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)58%💥 ExploitRealnetworks Helix Mobile ServerRealnetworks Helix ServerRealnetworks Helix Server Mobile20/4/201016/6/2026
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.5)1.6%—Realnetworks Helix DNA ServerRealnetworks Helix ServerRealnetworks Helix Server Mobile20/4/201016/6/2026
Heap-based buffer overflow in the NTLM authentication functionality in RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows remote attackers to have an unspecified impact via invalid base64-encoded data.
ModificadaMedia (5)4.2%—Realnetworks Helix PlayerRealnetworks Realplayer18/2/201016/6/2026
Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption.
ModificadaAlta (7.5)11%💥 ExploitRealnetworks Helix PlayerRealnetworks Realplayer18/2/201016/6/2026
Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is…
ModificadaAlta (9.3)8.5%—Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player25/1/201016/6/2026
Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows…
ModificadaAlta (9.3)6.8%—Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player25/1/201016/6/2026
Buffer overflow in the RTSPProtocol::HandleSetParameterRequest function in client/core/rtspprotocol.cpp in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x…
ModificadaAlta (9.3)6.8%—Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player25/1/201016/6/2026
Stack-based buffer overflow in protocol/rtsp/rtspclnt.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.x; RealPlayer SP 1.0.0 and 1.0.1; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, 11.0, and 11.0.1; Linux RealPlayer 10, 11.0.0, and 11.0.1; and Helix Player…
ModificadaAlta (9.3)7.3%—Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player25/1/201016/6/2026
Stack-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows user-assisted remote attackers to execute arbitrary code via a malformed…
ModificadaAlta (9.3)6.8%—Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player25/1/201016/6/2026
Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or…
ModificadaAlta (9.3)7.2%—Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player25/1/201016/6/2026
Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via an SIPR codec field…
ModificadaAlta (9.3)3.4%—Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player25/1/201016/6/2026
RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allow remote attackers to have an unspecified impact via a crafted media file that uses HTTP chunked transfer…
ModificadaAlta (9.3)8.5%—Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player25/1/201016/6/2026
Heap-based buffer overflow in the CGIFCodec::GetPacketBuffer function in datatype/image/gif/common/gifcodec.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix…
ModificadaAlta (9.3)7.1%—Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player25/1/201016/6/2026
Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a file with invalid…
ModificadaMedia (4.3)1.1%—Clixint Image Hosting Script DPI10/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in images.php in Image Hosting Script DPI 1.1 Final (1.1F) allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.2%💥 ExploitWebilix Wx-guestbook23/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.93%💥 ExploitWebilix Wx-guestbook23/9/200916/6/2026
Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)2.5%💥 ExploitMerlix Educate Server23/7/200916/6/2026
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request.
ModificadaMedia (5)2.7%💥 ExploitMerlix Educate Server23/7/200916/6/2026
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.
ModificadaMedia (5)8.8%💥 ExploitRealnetworks Helix ServerRealnetworks Helix Server Mobile20/7/200916/6/2026
RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI.
ModificadaMedia (5)3.4%💥 ExploitRealnetworks Helix ServerRealnetworks Helix Server Mobile20/7/200916/6/2026
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers.
ModificadaAlta (10)6.2%—Realnetworks Helix ServerRealnetworks Helix Server Mobile20/1/200916/6/2026
Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data,…
ModificadaMedia (5)2.6%💥 ExploitMerlix Teamworx Server16/12/200816/6/2026
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for teamworx.mdb.
ModificadaAlta (7.5)1.0%💥 ExploitMerlix Teamworx Server16/12/200816/6/2026
SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL commands via the password parameter (aka passwd field) in a login action. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)8.0%💥 ExploitToshiba Surveillix23/1/200816/6/2026
Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.
ModificadaMedia (4.3)2.8%💥 ExploitRealnetworks Helix PlayerRealnetworks Realplayer17/9/200716/6/2026
RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.
Orbitaley — Vulnerabilidades