Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Bpowerhouse Bpholidaylettings | 30/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bpowerhouse Bpmusic | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Bpowerhouse Bpstudents | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in students.php in BPowerHouse BPStudents 1.0 allows remote attackers to execute arbitrary SQL commands via the test parameter in a preview action. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bpowerhouse Bpgames | 30/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Bpowerhouse Bplawyercasedocuments | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | WEB Development House Alibaba Clone | 13/7/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Publicwarehouse Lightblog | 19/2/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) username parameter to view_member.php, (2) username_post parameter to login.php, and the (3) Lightblog_username cookie… | |
| Modificada | Alta (9.3) | 7.0% | — | Trend Micro Housecall | 23/12/2008 | 16/6/2026 | Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function. | |
| Modificada | Alta (9.3) | 7.0% | — | Trend Micro Housecall | 23/12/2008 | 16/6/2026 | The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to download an arbitrary library file onto a client system via a "custom update server" argument. NOTE: this can be leveraged for code execution by writing to a Startup folder. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Bpowerhouse Mini Blog | 16/12/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Bpowerhouse Mini CMS | 16/12/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters. | |
| Modificada | Media (6.8) | 5.7% | 💥 Exploit | Apple Core Image FUN House | 14/7/2008 | 16/6/2026 | Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a .funhouse file with a string XML element that contains many characters. | |
| Modificada | Media (4.4) | 2.4% | 💥 Exploit | Publicwarehouse Lightblog | 20/2/2008 | 16/6/2026 | Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the username parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Salims Softhouse JAF CMS | 27/11/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) show parameter to index.php and the (2) print parameter to print.php. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Media (5) | 1.4% | — | Distributed Checksum Clearinghouse DCC | 16/10/2007 | 16/6/2026 | Distributed Checksum Clearinghouse (DCC) 1.3.65 allows remote attackers to cause a denial of service (crash) via a "SOCKS flood." | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Lighthouse Development Squirrelcart | 21/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_isp_root parameter, probably related to cart.php. | |
| Modificada | Alta (10) | 7.6% | — | Realnetworks Gamehouse | 19/6/2007 | 16/6/2026 | Multiple buffer overflows in RealNetworks GameHouse dldisplay ActiveX control (ghdlctl.dll) allow remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Public Warehouse Light Blog | 8/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in add_comment.php in Light Blog 4.1 before 20070606 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Active WEB Softwares Active Auction House | 27/3/2007 | 16/6/2026 | SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Media (6.8) | 5.7% | 💥 Exploit | Salims Softhouse JAF CMS | 6/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the main_dir parameter to (1) forum/main.php and (2) forum/headlines.php. | |
| Modificada | Alta (7.5) | 7.5% | 💥 Exploit | Salims Softhouse JAF CMS | 6/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the website parameter. | |
| Modificada | Media (6.8) | 0.31% | — | Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client | 22/2/2007 | 16/6/2026 | Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836. | |
| Modificada | Alta (7.2) | 0.36% | — | Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client | 22/2/2007 | 16/6/2026 | The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been… | |
| Modificada | Alta (7.2) | 0.34% | — | Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client | 22/2/2007 | 16/6/2026 | Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not properly parse commands, which allows local users to gain privileges via unspecified vectors, aka CSCsh30624. | |
| Modificada | Media (6.8) | 0.31% | — | Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client | 22/2/2007 | 16/6/2026 | Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client use an insecure default Discretionary Access Control Lists (DACL) for the connection client GUI, which allows local… |