Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | URS Wolfer Kwebkitpart | 2/8/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536. | |
| Modificada | Baja (1.9) | 0.32% | — | Wolfram Research Mathematica | 24/5/2010 | 16/6/2026 | Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Wolfram Webmathematica | 27/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI to the MSP script. | |
| Modificada | Media (5) | 1.1% | — | Wolfram Webmathematica | 27/4/2010 | 16/6/2026 | Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message. | |
| Modificada | Alta (7.5) | 70% | 💥 Exploit | Oracle MysqlWolfssl YasslCanonical Ubuntu LinuxDebian Linux+1 | 30/12/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of… | |
| Modificada | Media (4.3) | 1.2% | — | Wolfgang Ziegler Temporary Invitation | 9/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Temporary Invitation module 5.x before 5.x-2.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Name field in an invitation. | |
| Modificada | Media (6.8) | 4.7% | — | Matt Kimball AND Roger Wolff MTR | 21/5/2008 | 16/6/2026 | Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the ns_name_ntop function in resolv/ns_name.c… | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Firewolf Technologies Synergiser | 3/11/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: this can be leveraged to obtain the path by including a local PHP script with a duplicate function… | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Timberwolf | 28/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the nid parameter. | |
| Modificada | Alta (7.6) | 7.6% | 💥 Exploit | ID Software Quake 3 ArenaID Software Quake 3 EngineID Software Return TO Castle WolfensteinID Software Wolfenstein Enemy Territory | 8/5/2006 | 16/6/2026 | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command. | |
| Modificada | Media (5) | 2.6% | — | Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+6 | 2/5/2005 | 16/6/2026 | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data. | |
| Modificada | Media (5) | 5.7% | 💥 Exploit | Wolfram Research Webmathematica | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the MSPStoreID parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Wolfram Research Mathematica | 13/2/2002 | 16/6/2026 | The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to bypass access control (specified by the -restrict argument) and steal a license via a client request that includes the name of a host that is allowed to obtain the license. | |
| Modificada | Media (5) | 1.6% | — | Wolfram Research Mathematica | 30/7/2001 | 16/6/2026 | The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests. | |
| Modificada | Baja (2.1) | 0.39% | — | Wolfram Schneider Makewhatis | 11/6/2001 | 16/6/2026 | makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters. | |
| Modificada | Alta (7.2) | 0.82% | 💥 Exploit | Matt Kimball AND Roger Wolff MTRTurbolinux | 3/3/2000 | 16/6/2026 | The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Wolfpack Development Xshipwars | 9/12/1999 | 16/6/2026 | Buffer overflow in Xshipwars xsw program. |