Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

304 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.5%💥 ExploitTeraway Filestream12/5/200916/6/2026
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.
ModificadaMedia (4.3)1.8%💥 ExploitIBM Tivoli Continuous Data Protection FOR Files17/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0 allows remote attackers to inject arbitrary web script or HTML via the reason parameter.
ModificadaAlta (9.3)5.7%—HP Openview Performance AgentInnermedia Dynazip MAXInnermedia Dynazip MAX SecureFilestream Turbozip13/4/200916/6/2026
Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code…
ModificadaMedia (5)11%💥 ExploitCodecall COM Ionfiles6/2/200916/6/2026
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
ModificadaAlta (7.5)1.00%💥 ExploitV3chat V3 Chat Profiles Dating Script31/12/200816/6/2026
SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.
ModificadaCrítica (9.8)7.1%💥 ExploitV3chat V3 Chat Profiles Dating Script31/12/200816/6/2026
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.
ModificadaAlta (7.5)1.0%💥 ExploitE107 Alternate Profiles Plugin29/10/200816/6/2026
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (9.3)6.9%💥 ExploitAlain Barbet Filesys Smbclientparser24/7/200816/6/2026
The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell metacharacters.
ModificadaAlta (9.3)4.8%—Tibco Adapter Files Z OSTibco HawkTibco Iprocess EngineTibco Rendezvous+411/4/200816/6/2026
Multiple buffer overflows in TIBCO Software Rendezvous before 8.1.0, as used in multiple TIBCO products, allow remote attackers to execute arbitrary code via a crafted message.
ModificadaMedia (6.8)21%💥 ExploitPhpprofiles27/2/200816/6/2026
PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.
ModificadaAlta (8.5)2.1%—Drupal Fileshare Module15/1/200816/6/2026
Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.
ModificadaMedia (5.8)4.1%—Ext2 Filesystems Utilities E2fsprogs7/12/200716/6/2026
Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.
ModificadaBaja (2.1)0.31%—IBM Tivoli Continuous Data Protection FOR Files5/11/200716/6/2026
IBM Tivoli Continuous Data Protection for Files (CDP) 3.1.0 uses weak permissions (unrestricted write) for the Central Admin Global download directory, which allows local users to place arbitrary files into a location used for updating CDP clients.
ModificadaMedia (5)9.5%💥 ExploitJoomla Rsfiles23/8/200716/6/2026
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter in a files.display action.
ModificadaAlta (7.5)1.2%💥 ExploitThecreativeheads.de Creative Files21/3/200716/6/2026
SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL commands via the dlid parameter.
ModificadaBaja (2.1)0.48%—Phpprofiles26/12/200616/6/2026
phpProfiles before 2.1.1 does not have an index.php or other index file in the (1) image_data, (2) graphics/comm, or (3) users read/write directories, which might allow remote attackers to list directory contents or have other unknown impacts.
ModificadaAlta (7.5)9.5%💥 ExploitPhpprofiles26/12/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php; or a URL in the incpath parameter to (3) index.inc.php, (4) account.inc.php, (5)…
ModificadaMedia (4.6)0.32%—Phpprofiles26/12/200616/6/2026
phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.
ModificadaMedia (6.8)6.2%💥 ExploitPhpprofiles1/11/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc parameter in users/include/upload_ht.inc.php.
ModificadaMedia (5)1.7%—Curtis Farnham Files Xaraya Module7/2/200616/6/2026
Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via ".." (dot dot) sequences.
ModificadaAlta (7.5)5.6%—Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+1530/11/200516/6/2026
Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.
ModificadaAlta (10)4.8%—Ares Fileshare3/8/200516/6/2026
Stack-based buffer overflow in Ares FileShare 1.1 allows remote attackers or local users to execute arbitrary code via a (1) long history parameter in the configuration file (ares.conf) or (2) long search string.
ModificadaMedia (5)1.3%—Planetdns Planetfileserver6/7/200516/6/2026
mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.
ModificadaMedia (4.6)0.36%—Rsnapshot Filesystem Snapshot Utility10/4/200516/6/2026
The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.
ModificadaAlta (7.5)2.5%—Snapfiles Whisper FTP Surfer27/7/200416/6/2026
Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.