Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

388 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)5.5%💥 ExploitIBM Installation Manager1/10/200916/6/2026
Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.
ModificadaAlta (7.5)1.2%—Vastal Mmorpg Zone30/9/200916/6/2026
SQL injection vulnerability in view_news.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter. NOTE: the game_id vector is already covered by CVE-2008-4460.
ModificadaAlta (7.5)1.1%—Vastal Agent Zone30/9/200916/6/2026
SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.5%💥 ExploitVastal DVD Zone30/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to inject arbitrary web script or HTML via the mag_id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitVastal DVD Zone30/9/200916/6/2026
SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter, a different vector than CVE-2008-4465.
ModificadaAlta (10)3.9%—SAP Crystal Reports Server24/9/200916/6/2026
Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco…
ModificadaAlta (10)1.6%—SAP Crystal Reports Server24/9/200916/6/2026
Heap-based buffer overflow in SAP Crystal Reports Server 2008 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable…
ModificadaMedia (5)1.6%—SAP Crystal Reports Server24/9/200916/6/2026
Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information.…
ModificadaAlta (9.3)3.3%—Decomputeur Toolbar Uninstaller25/8/200916/6/2026
Unspecified vulnerability in the update feature in Toolbar Uninstaller 1.0.2 allows remote attackers to force the download and execution of arbitrary files via attack vectors related to a "malformed update url and a malformed update website."
ModificadaMedia (4)2.2%💥 ExploitDigital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+219/8/200916/6/2026
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the…
ModificadaMedia (5)2.1%—Stalker-game S.t.a.l.k.e.r.\10/4/200916/6/2026
The MultipacketReciever::RecievePacket function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server termination) via a crafted packet without an expected 0xe0 or 0xe1 value, which triggers the INT3 instruction.
ModificadaMedia (5)2.0%—Stalker-game S.t.a.l.k.e.r.\10/4/200916/6/2026
Integer overflow in the NET_Compressor::Decompress function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server crash) via a crafted packet with a 0xc1 value that contains no compressed data, which triggers a copy of a large amount of memory.
ModificadaAlta (10)8.3%💥 ExploitStalker-game S.t.a.l.k.e.r.\10/4/200916/6/2026
Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decompress function.
ModificadaMedia (5)3.4%💥 ExploitStalker-game S.t.a.l.k.e.r.\10/4/200916/6/2026
S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception.
ModificadaAlta (7.5)0.97%💥 ExploitVastal Software Zone20/2/200916/6/2026
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
ModificadaMedia (6.9)0.35%—Oliver Gorwits Netdisco Mibs Installer8/12/200816/6/2026
netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file, related to the (1) netdisco-mibs-install and (2) netdisco-mibs-download scripts.
ModificadaAlta (8.5)2.3%💥 ExploitCoastal Coast24/10/200816/6/2026
PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute arbitrary PHP code via a URL in the sections_file parameter.
ModificadaAlta (7.5)1.0%💥 ExploitVastal I-tech Freelance Zone7/10/200816/6/2026
SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the coder_id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitVastal I-tech Share Zone7/10/200816/6/2026
SQL injection vulnerability in view_news.php in Vastal I-Tech Share Zone allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitVastal I-tech Toner Cart7/10/200816/6/2026
SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitVastal I-tech Cosmetics Zone7/10/200816/6/2026
SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitVastal I-tech DVD Zone7/10/200816/6/2026
SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitVastal I-tech MAG Zone7/10/200816/6/2026
SQL injection vulnerability in view_mags.php in Vastal I-Tech Mag Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitVastal I-tech Jobs Zone7/10/200816/6/2026
SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitVastal I-tech Visa Zone7/10/200816/6/2026
SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.