Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
301 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | OpensslFilezilla-project Filezilla ServerSiemens Application Processing Engine FirmwareSiemens CP 1543-1 Firmware+24 | 7/4/2014 | 17/6/2026 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to… | |
| Modificada | Media (6) | 1.1% | — | Widgetfactorylimited COM JCE | 30/8/2012 | 16/6/2026 | Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details… | |
| Modificada | Media (4.3) | 0.84% | — | Etomite | 8/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Etomite before 1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Webdynamite Projectbutler | 17/8/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter. | |
| Modificada | Alta (7.8) | 1.7% | — | Mitel Nupoint Messenger | 7/5/2009 | 16/6/2026 | The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Alta (9.3) | 19% | — | Research IN Motion Limited Blackberry Application WEB Loader | 10/2/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the Research in Motion RIM AxLoader ActiveX control in AxLoader.ocx and AxLoader.dll in BlackBerry Application Web Loader 1.0 allow remote attackers to execute arbitrary code via unspecified use of the (1) load or (2) loadJad method. | |
| Modificada | Alta (9.3) | 4.9% | — | Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite | 21/1/2009 | 16/6/2026 | The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to… | |
| Modificada | Alta (9.3) | 5.5% | — | Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite | 20/1/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via… | |
| Modificada | Alta (10) | 17% | 💥 Exploit | Insight-tech Yosemite Backup | 20/11/2008 | 16/6/2026 | Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platform, related to libytlindtb.so; or (2) cause a denial of service (application crash) and possibly execute arbitrary code on a Windows platform, related to ytwindtb.dll;… | |
| Modificada | Media (4.3) | 1.3% | — | Etomite | 19/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Etomite 0.6.1.4 Final allows remote attackers to inject arbitrary web script or HTML via $_SERVER['PHP_INFO']. NOTE: the vendor disputes this issue in a followup, stating that the affected variable is $_SERVER['PHP_SELF'], and "This is not an Etomite specific… | |
| Modificada | Baja (2.3) | 0.67% | — | Research IN Motion Limited Blackberry 7270 | 27/6/2007 | 16/6/2026 | Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers to cause a denial of service (blocked call reception and calling) via format string specifiers in an SIP INVITE message that lacks a host name in the Contact header. | |
| Modificada | Baja (2.3) | 0.60% | — | Research IN Motion Limited Blackberry 7270 | 27/6/2007 | 16/6/2026 | The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Etomite | 2/3/2007 | 16/6/2026 | Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files via an nfile[] parameter with a filename that contains a .php extension followed by a valid image extension such as .gif or .jpg, then… | |
| Modificada | Media (5.8) | 8.0% | 💥 Exploit | Etomite | 22/11/2006 | 16/6/2026 | Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the f parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php. | |
| Modificada | Media (6.8) | 1.4% | — | Etomite | 22/11/2006 | 16/6/2026 | SQL injection vulnerability in index.php in Etomite CMS 0.6.1.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Etomite | 12/10/2006 | 16/6/2026 | SQL injection vulnerability in Etomite Content Management System (CMS) before 0.6.1.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Webdynamite Projectbutler | 17/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to /classes/ scripts including (1) Cache.class.php, (2) Customer.class.php, (3) Performance.class.php, (4) Project.class.php, (5)… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Etomite | 27/7/2006 | 16/6/2026 | SQL injection vulnerability in manager/index.php in Etomite CMS 0.6.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (5.8) | 1.2% | — | Jadu Limited Jadu CMS | 11/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Jadu CMS allow remote attackers to inject arbitrary web script or HTML via the (1) forename, (2) surname, (3) reg_email, (4) email_conf, (5) company, (6) city, (7) postcode, or (8) telephone parameters to site/scripts/register.php. NOTE: the provenance of this… | |
| Modificada | Alta (7.5) | 3.0% | — | Etomite | 20/1/2006 | 16/6/2026 | Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter. | |
| Modificada | Media (4.6) | 0.76% | 💥 Exploit | Netleaf Limited Notjustbrowsing | 3/5/2005 | 16/6/2026 | NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges. | |
| Modificada | Media (5) | 1.6% | — | Mitel 3300 Integrated Communication Platform | 28/2/2005 | 16/6/2026 | The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum. | |
| Modificada | Alta (7.5) | 8.3% | 💥 Exploit | Isesam Gemitel | 15/4/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter. | |
| Modificada | Media (5) | 1.4% | — | Mitel 3300 Integrated Communications PlatformAI | 28/2/2004 | 16/6/2026 | The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie. | |
| Modificada | Media (5) | 1.4% | — | Clearswift Limited Mailsweeper | 31/12/2003 | 16/6/2026 | Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove. |