Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 21% | — | Microsoft Publisher | 16/12/2010 | 16/6/2026 | pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Graugon PHP Article Publisher | 23/4/2010 | 16/6/2026 | admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Graugon PHP Article Publisher | 23/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) c parameter to index.php and the (2) id parameter to view.php. | |
| Modificada | Alta (9.3) | 23% | — | Microsoft Publisher | 14/4/2010 | 16/6/2026 | Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability." | |
| Modificada | Media (4.3) | 2.8% | — | Webworks EpublisherWebworks HelpWebworks PublisherVmware Vcenter+6 | 16/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x… | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Nelogic Nephp Publisher | 23/9/2009 | 16/6/2026 | SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field. | |
| Modificada | Alta (9.3) | 29% | — | Microsoft Office Publisher | 15/7/2009 | 16/6/2026 | Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability." | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Gazatem Gnews Publisher | 30/12/2008 | 16/6/2026 | SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands via the authorID parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Scripts Frenzy Article Publisher PRO | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Scripts Frenzy Article Publisher PRO | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft AccessMicrosoft ExcelMicrosoft FrontpageMicrosoft Groove+13 | 7/7/2008 | 16/6/2026 | Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Comdev News Publisher | 17/4/2008 | 16/6/2026 | SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 37% | — | Microsoft Publisher | 12/2/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability." | |
| Modificada | Alta (9.3) | 29% | — | Microsoft OfficeMicrosoft Publisher | 12/2/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability." | |
| Modificada | Media (6.8) | 23% | 💥 Exploit | Netwerk Smart Publisher | 31/1/2008 | 16/6/2026 | Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filedata parameter. | |
| Modificada | Media (6.8) | 11% | — | Microsoft Publisher | 27/12/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted PUB file, possibly involving wordart. | |
| Modificada | Alta (9.3) | 33% | — | Microsoft Publisher | 10/7/2007 | 16/6/2026 | PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical… | |
| Modificada | Media (6.8) | 1.4% | — | Mobilepublisherphp | 18/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the auth_method parameter to (1) index.php, (2) list.php, (3) postreview.php, (4) reindex.php, (5) sections.php, (6) templates.php, (7) userinfo.php, (8) users.php, and (9) view.php in… | |
| Modificada | Alta (10) | 18% | — | Microsoft Publisher | 27/2/2007 | 16/6/2026 | Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable… | |
| Analizada | Alta (8.8) | 43% | ⚠ Explotación activa | Microsoft AccessMicrosoft ExcelMicrosoft Excel ViewerMicrosoft Frontpage+10 | 3/2/2007 | 16/6/2026 | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks. | |
| Modificada | Alta (7.5) | 1.1% | — | Superfreaker Studios Upublisher | 8/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Superfreaker Studios UPublisher 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (a) sendarticle.asp and (b) printarticle.asp, and the ID parameter to (c) index.asp and (d) preferences.asp, different vectors than CVE-2006-5888. | |
| Modificada | Alta (7.5) | 1.1% | — | Superfreaker Studios Upublisher | 8/12/2006 | 16/6/2026 | SQL injection vulnerability in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp. NOTE: the provenance of this information is unknown; details are obtained from third party sources. | |
| Modificada | Media (6.8) | 2.1% | — | Expinion.net Inews PublisherExpinion.net News Manager | 4/12/2006 | 16/6/2026 | SQL injection vulnerability in articles.asp in Expinion.net iNews (1) Publisher (iNP) 2.5 and earlier, and possibly (2) News Manager, allows remote attackers to execute arbitrary SQL commands via the ex parameter. NOTE: early reports of this issue reported it as XSS, but this was erroneous. The original report was for… | |
| Modificada | Media (6.8) | 1.3% | — | Expinion.net Inews Publisher | 1/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in articles.asp in Expinion.net iNews Publisher (iNP) 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the hl parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | — | Bpg-infotech Easy PublisherBpg-infotech Smart Publisher PRO | 24/11/2006 | 16/6/2026 | SQL injection vulnerability in bpg/publications_list.asp in BPG-InfoTech Easy Publisher and Smart Publisher//Pro 2.7.7 allows remote attackers to execute arbitrary SQL commands via the vjob parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. |