Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)3.5%—Mailenable EnterpriseMailenable ProfessionalMailenable Standard7/9/200616/6/2026
SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via an SPF lookup for a domain with a large number of records, which triggers a null pointer exception.
ModificadaMedia (5.1)3.1%—Cimmetry Systems Autovue Solidmodel Professional28/7/200616/6/2026
Stack-based buffer overflow in AutoVue SolidModel Professional Desktop Edition 19.1 Build 5993 allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) ARJ, (2) RAR, or (3) ZIP archive.
ModificadaMedia (5)1.2%—Professional Home Page Tools Guestbook25/7/200616/6/2026
delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obtain the administrator's password hash after logout.
ModificadaAlta (7.5)1.5%—Professional Home Page Tools Guestbook21/7/200616/6/2026
Multiple SQL injection vulnerabilities in class.php in Professional Home Page Tools Guestbook allow remote attackers to execute arbitrary SQL commands via the (1) hidemail, (2) name, (3) mail, (4) ip, or (5) text parameters.
ModificadaMedia (6.4)1.2%—Professional Home Page Tools Guestbook21/7/200616/6/2026
setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash.
ModificadaMedia (5)6.1%💥 ExploitMailenable EnterpriseMailenable Professional28/6/200616/6/2026
The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a…
ModificadaAlta (7.5)2.4%—Picturedis PhotoalbumPicturedis Professional19/6/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in PictureDis Professional 1.33 Build 234 and earlier and PictureDis Photoalbum 4.82 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to files in photoalbum/ including (1) thumstbl.php, (2) wpfiles.php, and (3)…
ModificadaMedia (6.5)1.1%—Hitachi EUR Print ServiceHitachi EUR Print Service FOR ILFHitachi EUR ProfessionalHitachi EUR Viewer22/5/200616/6/2026
SQL injection vulnerability in Hitachi EUR Professional Edition, EUR Viewer, EUR Print Service, and EUR Print Service for ILF allows remote authenticated users to execute arbitrary SQL commands via unknown attack vectors.
ModificadaMedia (5)5.5%—Ipswitch Whatsup Professional15/5/200616/6/2026
NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensitive information about network nodes via a modified nDeviceGroupID parameter.
ModificadaMedia (4.3)4.5%💥 ExploitIpswitch Whatsup Professional15/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b)…
ModificadaMedia (5)3.1%—Ipswitch Whatsup Professional15/5/200616/6/2026
NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users to other websites via the (1) sCancelURL and possibly (2) sRedirectUrl parameters.
ModificadaMedia (5)3.8%—Ipswitch Whatsup Professional15/5/200616/6/2026
NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium generates different error messages in a way that allows remote attackers to enumerate valid usernames. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaMedia (5)3.8%—Ipswitch Whatsup Professional15/5/200616/6/2026
Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)2.5%—Ipswitch Whatsup Professional15/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via unknown vectors in (1) NmConsole/Tools.asp and (2) NmConsole/DeviceSelection.asp. NOTE: the provenance of this information is…
ModificadaMedia (5)3.5%—Ipswitch Whatsup Professional15/5/200616/6/2026
Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain source code for scripts via a trailing dot in a request to NmConsole/Login.asp.
ModificadaAlta (10)1.8%—Mailenable EnterpriseMailenable ProfessionalMailenable Standard15/4/200616/6/2026
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to "authentication exploits". NOTE: this is a different set of affected versions, and probably a different…
ModificadaAlta (7.5)1.2%💥 ExploitInternet Solutions Professionals Site MAN2/4/200616/6/2026
SQL injection vulnerability in admin_login.asp in ISP of Egypt SiteMan allows remote attackers to execute arbitrary SQL commands via the pass parameter.
ModificadaMedia (5)2.4%—Mailenable EnterpriseMailenable Professional21/3/200616/6/2026
Webmail in MailEnable Professional Edition before 1.73 and Enterprise Edition before 1.21 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors involving "incorrectly encoded quoted-printable emails".
ModificadaMedia (5)2.3%—Mailenable Professional1/2/200616/6/2026
IMAP service in MailEnable Professional Edition before 1.72 allows remote attackers to cause a denial of service (service crash) via unspecified vectors involving the EXAMINE command.
ModificadaMedia (4.3)1.7%💥 ExploitDiscusware Discus FreewareDiscusware Discus Professional4/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message. NOTE: the provenance of this information is unknown;…
ModificadaAlta (7.8)7.1%💥 ExploitMailenable EnterpriseMailenable Professional21/12/200516/6/2026
Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) LIST, (2) LSUB, and (3) UID FETCH commands. NOTE: it is possible that these are alternate vectors for the issue…
ModificadaMedia (6.5)4.3%💥 ExploitMailenable EnterpriseMailenable Professional20/12/200516/6/2026
Buffer overflow in MailEnable Professional 1.71 and earlier, and Enterprise 1.1 and earlier, allows remote authenticated users to execute arbitrary code via a long IMAP EXAMINE command.
ModificadaMedia (4.3)1.9%💥 ExploitCfmagic Magic Book PersonalCfmagic Magic Book Professional12/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in book.cfm in Magic Book Personal and Professional 2.0 allows remote attackers to inject arbitrary web script or HTML via the StartRow parameter.
ModificadaAlta (7.8)2.1%—Soti Pocket Controller-professional11/12/200516/6/2026
Soti Pocket Controller-Professional 5.0 allows remote attackers to turn off, reboot, or hard reset a PDA via a series of initialization, command, and reset packets sent to port 5492.
ModificadaAlta (7.5)1.8%💥 ExploitWeb4future Edating Professional6/12/200516/6/2026
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.
Orbitaley — Vulnerabilidades