Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—URS Wolfer Kwebkitpart2/8/201016/6/2026
Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536.
ModificadaBaja (1.9)0.32%—Wolfram Research Mathematica24/5/201016/6/2026
Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.
ModificadaMedia (4.3)1.5%💥 ExploitWolfram Webmathematica27/4/201016/6/2026
Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI to the MSP script.
ModificadaMedia (5)1.1%—Wolfram Webmathematica27/4/201016/6/2026
Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message.
ModificadaAlta (7.5)70%💥 ExploitOracle MysqlWolfssl YasslCanonical Ubuntu LinuxDebian Linux+130/12/200916/6/2026
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of…
ModificadaMedia (4.3)1.2%—Wolfgang Ziegler Temporary Invitation9/11/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Temporary Invitation module 5.x before 5.x-2.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Name field in an invitation.
ModificadaMedia (6.8)4.7%—Matt Kimball AND Roger Wolff MTR21/5/200816/6/2026
Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the ns_name_ntop function in resolv/ns_name.c…
ModificadaAlta (7.5)3.9%💥 ExploitFirewolf Technologies Synergiser3/11/200716/6/2026
Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: this can be leveraged to obtain the path by including a local PHP script with a duplicate function…
ModificadaMedia (6.8)2.1%💥 ExploitTimberwolf28/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the nid parameter.
ModificadaAlta (7.6)7.6%💥 ExploitID Software Quake 3 ArenaID Software Quake 3 EngineID Software Return TO Castle WolfensteinID Software Wolfenstein Enemy Territory8/5/200616/6/2026
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command.
ModificadaMedia (5)2.6%—Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+62/5/200516/6/2026
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data.
ModificadaMedia (5)5.7%💥 ExploitWolfram Research Webmathematica4/10/200216/6/2026
Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the MSPStoreID parameter.
ModificadaAlta (7.5)1.6%—Wolfram Research Mathematica13/2/200216/6/2026
The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to bypass access control (specified by the -restrict argument) and steal a license via a client request that includes the name of a host that is allowed to obtain the license.
ModificadaMedia (5)1.6%—Wolfram Research Mathematica30/7/200116/6/2026
The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests.
ModificadaBaja (2.1)0.39%—Wolfram Schneider Makewhatis11/6/200116/6/2026
makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.
ModificadaAlta (7.2)0.82%💥 ExploitMatt Kimball AND Roger Wolff MTRTurbolinux3/3/200016/6/2026
The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.
ModificadaAlta (7.5)2.1%💥 ExploitWolfpack Development Xshipwars9/12/199916/6/2026
Buffer overflow in Xshipwars xsw program.