Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Tapatalk | 9/9/2014 | 17/6/2026 | The Tapatalk (aka com.quoord.tapatalkpro.activity) application 4.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.8) | 3.2% | — | Rockwellautomation Factorytalk Services Platform | 18/4/2013 | 16/6/2026 | Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that specifies a… | |
| Modificada | Alta (7.8) | 3.2% | — | Rockwellautomation Factorytalk Services Platform | 18/4/2013 | 16/6/2026 | Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that… | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | FusetalkFusetalk. Fusetalk | 4/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter. | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft OfficeMicrosoft Office WEB ComponentsMicrosoft SQL Server 2000Microsoft SQL Server 2005+6 | 10/4/2012 | 16/6/2026 | The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce… | |
| Modificada | Media (5) | 3.5% | — | Rockwellautomation FactorytalkRockwellautomation Rslogix 5000 | 2/4/2012 | 16/6/2026 | The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet. | |
| Modificada | Media (5) | 10% | 💥 Exploit | Rockwellautomation FactorytalkRockwellautomation Rslogix 5000 | 2/4/2012 | 16/6/2026 | The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet. | |
| Modificada | Alta (10) | 1.4% | — | Kktalk | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in the KKtalk (com.kkliaotian.android) application 4.0.0 and 4.1.5 for Android has unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.86% | — | Qualcomm Yagattatalk Messenger | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in the YagattaTalk Messenger (com.iskoot.yagatta.yagattatalk) application 1.00.01.08 for Android has unknown impact and attack vectors. | |
| Modificada | Alta (10) | 1.4% | — | Uangel Realtalk | 7/3/2012 | 16/6/2026 | Unspecified vulnerability in the RealTalk (com.tmsmanager.tms) application A.0.9.250 for Android has unknown impact and attack vectors. | |
| Modificada | Media (6.4) | 1.0% | — | Xiaomi Mitalk Messenger | 25/1/2012 | 16/6/2026 | The Xiaomi MiTalk Messenger (com.xiaomi.channel) application before 2.1.320 for Android does not properly protect data, which allows remote attackers to read or modify messaging information via a crafted application. | |
| Modificada | Alta (9.3) | 3.3% | — | Renren Talk | 24/1/2012 | 16/6/2026 | Heap-based buffer overflow in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via a crafted image in a chat message, as demonstrated using a PNG file. | |
| Modificada | Alta (9.3) | 3.3% | — | Renren Talk | 24/1/2012 | 16/6/2026 | Integer signedness error in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via crafted dimensions of a skin file, leading to a heap-based buffer overflow, as demonstrated using a BMP image. | |
| Modificada | Media (6.9) | 0.64% | — | Rockwellautomation Factorytalk Diagnostics Viewer | 28/7/2011 | 16/6/2026 | Unspecified vulnerability in Rockwell Automation FactoryTalk Diagnostics Viewer before V2.30.00 (CPR9 SR3) allows local users to execute arbitrary code via a crafted FactoryTalk Diagnostics Viewer (.ftd) configuration file, which triggers memory corruption. | |
| Modificada | Alta (7.5) | 2.5% | — | Wildbit Beanstalkd | 8/6/2010 | 16/6/2026 | The put command functionality in beanstalkd 1.4.5 and earlier allows remote attackers to execute arbitrary Beanstalk commands via the body in a job that is too big, which is not properly handled by the dispatch_cmd function in prot.c. | |
| Modificada | Media (6.4) | 2.6% | 💥 Exploit | Scripts.oldguy Talkback | 26/5/2010 | 16/6/2026 | TalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify comments. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Scripts.oldguy Talkback | 7/5/2010 | 16/6/2026 | addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Stefan Tannhaeuser Tv21 Talkshow | 15/1/2010 | 16/6/2026 | SQL injection vulnerability in the TV21 Talkshow (tv21_talkshow) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 0.85% | — | Stefan Tannhaeuser Tv21 Talkshow | 15/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the TV21 Talkshow (tv21_talkshow) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 29% | — | Microsoft Biztalk ServerMicrosoft Internet Security AND Acceleration ServerMicrosoft OfficeMicrosoft Office WEB Components+1 | 12/8/2009 | 16/6/2026 | Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1,… | |
| Modificada | Media (5) | 2.1% | — | Stalker-game S.t.a.l.k.e.r.\ | 10/4/2009 | 16/6/2026 | The MultipacketReciever::RecievePacket function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server termination) via a crafted packet without an expected 0xe0 or 0xe1 value, which triggers the INT3 instruction. | |
| Modificada | Media (5) | 2.0% | — | Stalker-game S.t.a.l.k.e.r.\ | 10/4/2009 | 16/6/2026 | Integer overflow in the NET_Compressor::Decompress function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server crash) via a crafted packet with a 0xc1 value that contains no compressed data, which triggers a copy of a large amount of memory. | |
| Modificada | Alta (10) | 8.3% | 💥 Exploit | Stalker-game S.t.a.l.k.e.r.\ | 10/4/2009 | 16/6/2026 | Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decompress function. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Stalker-game S.t.a.l.k.e.r.\ | 10/4/2009 | 16/6/2026 | S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception. | |
| Modificada | Alta (9.3) | 4.5% | — | Netatalk | 26/12/2008 | 16/6/2026 | The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title. |