Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.99% | — | Tropos Mesh OSTropos 1310 Distrubution Automation Mesh RouterTropos 1410 Mesh RouterTropos 1410 Wireless Mesh Router+5 | 18/12/2012 | 16/6/2026 | Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Peter Kovacs Timesheet Next GEN | 19/9/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Truworthit Flex Timesheet | 27/4/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Intermesh Group-office | 16/9/2010 | 16/6/2026 | SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a category action. | |
| Modificada | Media (4.3) | 0.83% | — | Pacifictimesheet Pacific Timesheet | 28/5/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Ultrize Timesheet | 10/9/2009 | 16/6/2026 | Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter. | |
| Modificada | Media (6.8) | 1.7% | 💥 Exploit | Ultrize Timesheet | 14/8/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter. | |
| Modificada | Alta (10) | 6.8% | 💥 Exploit | Imesh.com Imesh | 20/12/2007 | 16/6/2026 | The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to execute arbitrary code via a certain argument to the SetHandler method. | |
| Modificada | Alta (7.1) | 1.5% | — | Imesh.com Imesh | 20/12/2007 | 16/6/2026 | The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via an empty string in the argument to the ProcessRequestEx method. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Vladimir Meshakov Bubla | 31/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the bu_dir parameter to (1) bu/bu_claro.php, (2) bu/bu_cache.php, or (3) bu/bu_parse.php, different vectors and a different affected version… | |
| Modificada | Media (5) | 1.2% | — | Dominic Gamble Timesheet.php | 12/9/2006 | 16/6/2026 | SQL injection vulnerability in login.php in dwayner79 and Dominic Gamble Timesheet (aka Timesheet.php) 1.2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Carey Briggs PHP Mysql Timesheet | 15/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php. | |
| Modificada | Alta (10) | 6.0% | — | Mesh ViewerAI | 10/1/2005 | 16/6/2026 | Buffer overflow in the Mesh::type method in mesh.c for the mview program in Mesh Viewer 0.2.2 allows remote attackers to execute arbitrary code via crafted mesh files. | |
| Modificada | Alta (7.5) | 2.6% | — | Imesh.com Imesh | 29/6/2000 | 16/6/2026 | Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port. |