Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Alta (7.5) | 1.3% | — | Mxmania Calendar MX Basic | 29/12/2006 | 16/6/2026 | Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for calendar.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mxmania Calendar MX Basic | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Basicforum | 1/12/2006 | 16/6/2026 | SQL injection vulnerability in edit.asp in BasicForum 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 6.8% | — | Microsoft Visual Basic | 13/9/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Visual Basic (VB) 6 has an unknown impact ("overflow") via a project that contains a certain Click event procedure, as demonstrated using the msgbox function and the VB.Label object. | |
| Modificada | Media (5.1) | 10% | — | Microsoft Visual Basic | 9/8/2006 | 16/6/2026 | Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via… | |
| Modificada | Media (5.1) | 1.9% | 💥 Exploit | Geodesicsolutions Geoauctions PremierGeodesicsolutions Geoclassifieds Basic | 25/7/2006 | 16/6/2026 | SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter. | |
| Modificada | Media (5.1) | 1.9% | — | Vincent HOR Calendarix Basic | 19/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Calendarix Basic 0.7.20060401 and earlier, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) cal_event.php and (2) cal_popup.php. | |
| Modificada | Media (4) | 49% | 💥 Exploit | Kevin Johnson Basic Analysis AND Security Engine | 31/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BASE_path parameter to (1) base_qry_common.php, (2) base_stat_common.php, and (3) includes/base_include.inc.php. | |
| Modificada | Media (4.3) | 4.1% | 💥 Exploit | Kevin Johnson Basic Analysis AND Security EngineRoman Danyliw Analysis Console FOR Intrusion Databases (acid) | 3/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows remote attackers to inject arbitrary web script or HTML via the (a) back parameter to base_graph_main.php, (b) netmask… | |
| Modificada | Media (5) | 1.7% | — | Basic Analysis AND Security Engine Base | 30/3/2006 | 16/6/2026 | base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes". | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Acid Analysis Console FOR Intrusion DatabasesSecureideas Basic Analysis AND Security Engine | 27/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to execute arbitrary SQL commands via… | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation. | |
| Modificada | Alta (10) | 55% | 💥 Exploit | Microsoft OfficeMicrosoft ProjectMicrosoft VisioMicrosoft Visual Basic | 20/10/2003 | 16/6/2026 | Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter. | |
| Modificada | Alta (7.5) | 12% | — | Microsoft Visual BasicMicrosoft Visual Studio | 3/5/2001 | 16/6/2026 | Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (4.6) | 1.2% | — | Microsoft OfficeMicrosoft OutlookMicrosoft ProjectMicrosoft Visual Basic+2 | 1/1/1999 | 16/6/2026 | The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. |