Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

323 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)21%—Microsoft Publisher16/12/201016/6/2026
pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher…
ModificadaAlta (7.5)2.8%💥 ExploitGraugon PHP Article Publisher23/4/201016/6/2026
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1.
ModificadaAlta (7.5)0.97%💥 ExploitGraugon PHP Article Publisher23/4/201016/6/2026
Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) c parameter to index.php and the (2) id parameter to view.php.
ModificadaAlta (9.3)23%—Microsoft Publisher14/4/201016/6/2026
Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."
ModificadaMedia (4.3)2.8%—Webworks EpublisherWebworks HelpWebworks PublisherVmware Vcenter+616/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x…
ModificadaAlta (7.5)0.96%💥 ExploitNelogic Nephp Publisher23/9/200916/6/2026
SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.
ModificadaAlta (9.3)29%—Microsoft Office Publisher15/7/200916/6/2026
Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."
ModificadaAlta (7.5)0.97%💥 ExploitGazatem Gnews Publisher30/12/200816/6/2026
SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands via the authorID parameter.
ModificadaAlta (7.5)1.00%💥 ExploitScripts Frenzy Article Publisher PRO4/11/200816/6/2026
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.
ModificadaAlta (7.5)0.97%💥 ExploitScripts Frenzy Article Publisher PRO4/11/200816/6/2026
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaAlta (7.5)17%—Microsoft AccessMicrosoft ExcelMicrosoft FrontpageMicrosoft Groove+137/7/200816/6/2026
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times…
ModificadaAlta (7.5)0.97%💥 ExploitComdev News Publisher17/4/200816/6/2026
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (10)37%—Microsoft Publisher12/2/200816/6/2026
Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."
ModificadaAlta (9.3)29%—Microsoft OfficeMicrosoft Publisher12/2/200816/6/2026
Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."
ModificadaMedia (6.8)23%💥 ExploitNetwerk Smart Publisher31/1/200816/6/2026
Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filedata parameter.
ModificadaMedia (6.8)11%—Microsoft Publisher27/12/200716/6/2026
Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted PUB file, possibly involving wordart.
ModificadaAlta (9.3)33%—Microsoft Publisher10/7/200716/6/2026
PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical…
ModificadaMedia (6.8)1.4%—Mobilepublisherphp18/4/200716/6/2026
PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the auth_method parameter to (1) index.php, (2) list.php, (3) postreview.php, (4) reindex.php, (5) sections.php, (6) templates.php, (7) userinfo.php, (8) users.php, and (9) view.php in…
ModificadaAlta (10)18%—Microsoft Publisher27/2/200716/6/2026
Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable…
AnalizadaAlta (8.8)43%⚠ Explotación activaMicrosoft AccessMicrosoft ExcelMicrosoft Excel ViewerMicrosoft Frontpage+103/2/200716/6/2026
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
ModificadaAlta (7.5)1.1%—Superfreaker Studios Upublisher8/12/200616/6/2026
Multiple SQL injection vulnerabilities in Superfreaker Studios UPublisher 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (a) sendarticle.asp and (b) printarticle.asp, and the ID parameter to (c) index.asp and (d) preferences.asp, different vectors than CVE-2006-5888.
ModificadaAlta (7.5)1.1%—Superfreaker Studios Upublisher8/12/200616/6/2026
SQL injection vulnerability in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
ModificadaMedia (6.8)2.1%—Expinion.net Inews PublisherExpinion.net News Manager4/12/200616/6/2026
SQL injection vulnerability in articles.asp in Expinion.net iNews (1) Publisher (iNP) 2.5 and earlier, and possibly (2) News Manager, allows remote attackers to execute arbitrary SQL commands via the ex parameter. NOTE: early reports of this issue reported it as XSS, but this was erroneous. The original report was for…
ModificadaMedia (6.8)1.3%—Expinion.net Inews Publisher1/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in articles.asp in Expinion.net iNews Publisher (iNP) 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the hl parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.1%—Bpg-infotech Easy PublisherBpg-infotech Smart Publisher PRO24/11/200616/6/2026
SQL injection vulnerability in bpg/publications_list.asp in BPG-InfoTech Easy Publisher and Smart Publisher//Pro 2.7.7 allows remote attackers to execute arbitrary SQL commands via the vjob parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Orbitaley — Vulnerabilidades