Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 5.5% | 💥 Exploit | IBM Installation Manager | 1/10/2009 | 16/6/2026 | Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname. | |
| Modificada | Alta (7.5) | 1.2% | — | Vastal Mmorpg Zone | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in view_news.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter. NOTE: the game_id vector is already covered by CVE-2008-4460. | |
| Modificada | Alta (7.5) | 1.1% | — | Vastal Agent Zone | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Vastal DVD Zone | 30/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to inject arbitrary web script or HTML via the mag_id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Vastal DVD Zone | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter, a different vector than CVE-2008-4465. | |
| Modificada | Alta (10) | 3.9% | — | SAP Crystal Reports Server | 24/9/2009 | 16/6/2026 | Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco… | |
| Modificada | Alta (10) | 1.6% | — | SAP Crystal Reports Server | 24/9/2009 | 16/6/2026 | Heap-based buffer overflow in SAP Crystal Reports Server 2008 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable… | |
| Modificada | Media (5) | 1.6% | — | SAP Crystal Reports Server | 24/9/2009 | 16/6/2026 | Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information.… | |
| Modificada | Alta (9.3) | 3.3% | — | Decomputeur Toolbar Uninstaller | 25/8/2009 | 16/6/2026 | Unspecified vulnerability in the update feature in Toolbar Uninstaller 1.0.2 allows remote attackers to force the download and execution of arbitrary files via attack vectors related to a "malformed update url and a malformed update website." | |
| Modificada | Media (4) | 2.2% | 💥 Exploit | Digital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+2 | 19/8/2009 | 16/6/2026 | The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the… | |
| Modificada | Media (5) | 2.1% | — | Stalker-game S.t.a.l.k.e.r.\ | 10/4/2009 | 16/6/2026 | The MultipacketReciever::RecievePacket function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server termination) via a crafted packet without an expected 0xe0 or 0xe1 value, which triggers the INT3 instruction. | |
| Modificada | Media (5) | 2.0% | — | Stalker-game S.t.a.l.k.e.r.\ | 10/4/2009 | 16/6/2026 | Integer overflow in the NET_Compressor::Decompress function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server crash) via a crafted packet with a 0xc1 value that contains no compressed data, which triggers a copy of a large amount of memory. | |
| Modificada | Alta (10) | 8.3% | 💥 Exploit | Stalker-game S.t.a.l.k.e.r.\ | 10/4/2009 | 16/6/2026 | Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decompress function. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Stalker-game S.t.a.l.k.e.r.\ | 10/4/2009 | 16/6/2026 | S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Vastal Software Zone | 20/2/2009 | 16/6/2026 | SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Media (6.9) | 0.35% | — | Oliver Gorwits Netdisco Mibs Installer | 8/12/2008 | 16/6/2026 | netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file, related to the (1) netdisco-mibs-install and (2) netdisco-mibs-download scripts. | |
| Modificada | Alta (8.5) | 2.3% | 💥 Exploit | Coastal Coast | 24/10/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute arbitrary PHP code via a URL in the sections_file parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal I-tech Freelance Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the coder_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal I-tech Share Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in view_news.php in Vastal I-Tech Share Zone allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Vastal I-tech Toner Cart | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal I-tech Cosmetics Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal I-tech DVD Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal I-tech MAG Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in view_mags.php in Vastal I-Tech Mag Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal I-tech Jobs Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal I-tech Visa Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter. |