Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%💥 ExploitBpowerhouse Bpholidaylettings30/9/200916/6/2026
Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters.
ModificadaAlta (7.5)0.99%💥 ExploitBpowerhouse Bpmusic30/9/200916/6/2026
SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter.
ModificadaAlta (7.5)1.2%—Bpowerhouse Bpstudents30/9/200916/6/2026
SQL injection vulnerability in students.php in BPowerHouse BPStudents 1.0 allows remote attackers to execute arbitrary SQL commands via the test parameter in a preview action.
ModificadaAlta (7.5)0.99%💥 ExploitBpowerhouse Bpgames30/9/200916/6/2026
Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php.
ModificadaAlta (7.5)0.96%💥 ExploitBpowerhouse Bplawyercasedocuments30/9/200916/6/2026
SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
ModificadaAlta (7.5)1.0%💥 ExploitWEB Development House Alibaba Clone13/7/200916/6/2026
Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is…
ModificadaMedia (6.8)1.9%💥 ExploitPublicwarehouse Lightblog19/2/200916/6/2026
Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) username parameter to view_member.php, (2) username_post parameter to login.php, and the (3) Lightblog_username cookie…
ModificadaAlta (9.3)7.0%—Trend Micro Housecall23/12/200816/6/2026
Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function.
ModificadaAlta (9.3)7.0%—Trend Micro Housecall23/12/200816/6/2026
The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to download an arbitrary library file onto a client system via a "custom update server" argument. NOTE: this can be leveraged for code execution by writing to a Startup folder.
ModificadaAlta (7.5)2.5%💥 ExploitBpowerhouse Mini Blog16/12/200816/6/2026
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters.
ModificadaAlta (7.5)2.4%💥 ExploitBpowerhouse Mini CMS16/12/200816/6/2026
Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters.
ModificadaMedia (6.8)5.7%💥 ExploitApple Core Image FUN House14/7/200816/6/2026
Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a .funhouse file with a string XML element that contains many characters.
ModificadaMedia (4.4)2.4%💥 ExploitPublicwarehouse Lightblog20/2/200816/6/2026
Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the username parameter.
ModificadaMedia (4.3)1.0%—Salims Softhouse JAF CMS27/11/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) show parameter to index.php and the (2) print parameter to print.php. NOTE: the provenance of this information is unknown; the details are…
ModificadaMedia (5)1.4%—Distributed Checksum Clearinghouse DCC16/10/200716/6/2026
Distributed Checksum Clearinghouse (DCC) 1.3.65 allows remote attackers to cause a denial of service (crash) via a "SOCKS flood."
ModificadaAlta (7.5)2.4%💥 ExploitLighthouse Development Squirrelcart21/8/200716/6/2026
PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_isp_root parameter, probably related to cart.php.
ModificadaAlta (10)7.6%—Realnetworks Gamehouse19/6/200716/6/2026
Multiple buffer overflows in RealNetworks GameHouse dldisplay ActiveX control (ghdlctl.dll) allow remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (4.3)1.1%—Public Warehouse Light Blog8/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in add_comment.php in Light Blog 4.1 before 20070606 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitActive WEB Softwares Active Auction House27/3/200716/6/2026
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaMedia (6.8)5.7%💥 ExploitSalims Softhouse JAF CMS6/3/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the main_dir parameter to (1) forum/main.php and (2) forum/headlines.php.
ModificadaAlta (7.5)7.5%💥 ExploitSalims Softhouse JAF CMS6/3/200716/6/2026
PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the website parameter.
ModificadaMedia (6.8)0.31%—Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client22/2/200716/6/2026
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836.
ModificadaAlta (7.2)0.36%—Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client22/2/200716/6/2026
The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been…
ModificadaAlta (7.2)0.34%—Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client22/2/200716/6/2026
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not properly parse commands, which allows local users to gain privileges via unspecified vectors, aka CSCsh30624.
ModificadaMedia (6.8)0.31%—Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client22/2/200716/6/2026
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client use an insecure default Discretionary Access Control Lists (DACL) for the connection client GUI, which allows local…
Orbitaley — Vulnerabilidades