Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Tuned Studios Classic ThemeTuned Studios EndlessTuned Studios Freeze ThemeTuned Studios Lonely Maple+3 | 11/1/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) Endless, (6) Classic Theme, and (7) Music Theme webpage templates allow remote attackers to include and execute arbitrary files via ".." sequences in the page parameter.… | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Multimedia Dance Music Module FOR Phpnuke | 26/9/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an ACCEPT_FILE array parameter to modules.php. | |
| Modificada | Media (6.8) | 2.1% | — | IrssiKristof Korwisi IxmmsaMikachu L33t Xmms Music Showing ScriptRicardo Mesquita Mpg123+3 | 18/8/2007 | 16/6/2026 | Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) a2x 0.0.1, (5) Another xmms-info script 1.0, (6) XChat-XMMS 0.8.1, and other unspecified scripts for XChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Easybe 1-2-3 Music Store | 3/7/2007 | 16/6/2026 | SQL injection vulnerability in process.php in Easybe 1-2-3 Music Store allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Gmtt Music Distro | 30/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in showown.php in GMTT Music Distro 1.2 allows remote attackers to inject arbitrary web script or HTML via the st parameter. | |
| Modificada | Alta (10) | 7.8% | 💥 Exploit | Sienzo Digital Music Mentor | 18/5/2007 | 16/6/2026 | Buffer overflow in the UnlockSupport function in the LockModules subsystem in a certain ActiveX control in ltmm15.dll in Sienzo Digital Music Mentor (DMM) 2.6.0.4 allows remote attackers to execute arbitrary code via a long string in the second argument, a different issue than CVE-2007-2564. | |
| Modificada | Alta (10) | 4.8% | — | Sienzo Digital Music Mentor | 9/5/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Sienzo Digital Music Mentor (DMM) 2.6.0.4 ActiveX control (DSKernel2.dll) allow remote attackers to execute arbitrary code via a long argument to the (1) LockModules or (2) UnlockModule function. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | LibmusicbrainzLibmusicbrainz SVN | 17/8/2006 | 16/6/2026 | Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Musicbox | 27/7/2006 | 16/6/2026 | SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a request for the top-level URI. NOTE: the start parameter/search action is already covered by CVE-2006-1807, and the show parameter/top action… | |
| Modificada | Media (4.3) | 1.2% | — | Musicbox | 27/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a request for the top-level URI. NOTE: the id parameter in index.php, and the type and show parameters in a top action, are already covered by… | |
| Modificada | Media (5) | 1.2% | — | Musicbox | 27/7/2006 | 16/6/2026 | Shalwan MusicBox 2.3.4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. | |
| Modificada | Alta (7.6) | 10% | 💥 Exploit | Dynamic Universal Music Bibliotheque Dumb | 18/7/2006 | 16/6/2026 | Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 20060716, including libdumb, allows user-assisted attackers to execute arbitrary code via a ".it" (Impulse Tracker) file with an envelope with a large number of nodes. | |
| Modificada | Alta (7.5) | 1.4% | — | Musicbox | 18/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action. | |
| Modificada | Baja (2.6) | 1.3% | — | Musicbox | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action. | |
| Modificada | Alta (7.5) | 1.3% | — | Musicbox | 23/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index.php; or the (4) message1 or (5) message parameter to (b) cart.php. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Musicbox | 22/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top action in (a) index.php; and the (4) message1 parameter in (b) cart.php. | |
| Modificada | Media (5.1) | 3.0% | — | Illustrate Dbpoweramp Music Converter | 31/12/2005 | 16/6/2026 | Buffer overflow in Illustrate dBpowerAMP Music Converter 11.5 and earlier, possibly including (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe, allows user-assisted attackers to cause a denial of service or execute arbitrary code via a .m3u playlist with a long entry, possibly involving large field names, as… | |
| Modificada | Media (5) | 1.1% | 💥 Exploit | Sergids TOP Music Module | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) idalbum parameters to modules.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Musicbox | 22/12/2005 | 16/6/2026 | SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Easybe 1-2-3 Music Store | 27/11/2005 | 16/6/2026 | SQL injection vulnerability in process.php in 1-2-3 music store allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter. | |
| Modificada | Baja (2.1) | 0.31% | — | Musicmatch Jukebox | 2/5/2005 | 16/6/2026 | Musicmatch 10.00.2047 and earlier store log files in the Program Files directory instead of the user profile, which may allow local users to obtain sensitive information. | |
| Modificada | Media (5) | 1.1% | — | Musicmatch Jukebox | 2/5/2005 | 16/6/2026 | DiagCollectionControl.dll in Musicmatch 10.00.2047 and earlier allows remote attackers to overwrite arbitrary files via the bstrSavePath argument. | |
| Modificada | Media (6.8) | 1.1% | — | Musicmatch Jukebox | 2/5/2005 | 16/6/2026 | Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks. | |
| Modificada | Media (4.6) | 0.34% | — | Musicmatch Jukebox | 2/5/2005 | 16/6/2026 | Unquoted Windows search path vulnerability in Musicmatch Jukebox 10.00.2047 and earlier allows local users to gain privileges via a malicious C:\program.exe file, which is run by MMFWLaunch.exe when it attempts to execute launch.exe. |