Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | Craftysyntax Crafty Syntax | 23/9/2011 | 16/6/2026 | Crafty Syntax 3.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by README_FILES/livehelp.php and certain other files. | |
| Modificada | Alta (9.3) | 3.4% | — | Blizzard Warcraft 3 THE Frozen Throne | 20/4/2010 | 16/6/2026 | Unspecified vulnerability in the JASS script interpreter in Warcraft III: The Frozen Throne 1.24b and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted custom map. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 2.2% | — | Code-crafters Ability Mail Server | 28/9/2009 | 16/6/2026 | Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Craftsilicon Banking@home | 25/2/2009 | 16/6/2026 | SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginName parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Php-fusion World OF Warcraft Tracker Infusion Module | 9/10/2008 | 16/6/2026 | SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter. | |
| Modificada | Media (6.8) | 3.3% | 💥 Exploit | Acoustica Beatcraft | 15/9/2008 | 16/6/2026 | Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of service or execute arbitrary code via a Beatcraft Project (aka bcproj) file with a long string in a certain instruments title field. | |
| Modificada | Alta (9.3) | 9.9% | 💥 Exploit | Acoustica Mixcraft | 2/9/2008 | 16/6/2026 | Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execute arbitrary code via a crafted .mx4 file. NOTE: it was later reported that version 3 is also affected. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Craftysyntax Crafty Syntax Live Help | 27/8/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php. | |
| Modificada | Media (5) | 1.2% | — | Craftysyntax Crafty Syntax Live Help | 27/8/2008 | 16/6/2026 | Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Crafty Syntax Live Help | 7/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Crafty Syntax Live Help | 6/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Crafty Syntax Live Help (CSLH) before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) livehelp.php, (2) user_questions.php, and (3) leavemessage.php. NOTE: the lostsheep.php vector is covered by CVE-2008-0848. | |
| Modificada | Media (4.3) | 1.3% | — | Crafty Syntax Live Help | 21/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in lostsheep.php in Crafty Syntax Live Help (CSLH) before 2.14.16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the versions claimed by the original researcher are probably incorrect. | |
| Modificada | Media (4) | 1.4% | — | Code-crafters Ability Mail Server | 23/11/2007 | 16/6/2026 | Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and possibly (2) a blank string in unspecified messages. | |
| Modificada | Media (4.3) | 6.2% | 💥 Exploit | Blizzard Entertainment Starcraft Brood WAR | 31/8/2007 | 16/6/2026 | Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed map, which triggers an out-of-bounds read during a minimap preview. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Crafty Syntax Image Gallery | 7/4/2006 | 16/6/2026 | SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $projectid variable is less than 1, which prevents the $limitquery_s… | |
| Modificada | Alta (9) | 4.2% | 💥 Exploit | Crafty Syntax Image Gallery | 7/4/2006 | 16/6/2026 | newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php. | |
| Modificada | Media (6.4) | 5.8% | 💥 Exploit | Juliusz Julas Gonera Warcraft III Replay Parser PHP | 2/4/2006 | 16/6/2026 | Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to fopen function calls or file uploads. NOTE: post-disclosure analysis by CVE suggests that the "page" parameter is not used in this… | |
| Modificada | Media (5.8) | 1.2% | — | Juliusz Julas Gonera Warcraft III Replay Parser PHP | 2/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: post-disclosure analysis by CVE suggests that the "page" parameter is not used in this product, and "id" might be the affected… | |
| Modificada | Media (6.4) | 8.1% | 💥 Exploit | Digicraft Software YAK | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..\" sequences in commands such as (1) dir or (2) put. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Crafty Syntax Live Help | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the name field of a livehelp or chat session. | |
| Modificada | Alta (7.8) | 2.0% | — | Code-crafters Ability Mail Server | 31/12/2004 | 16/6/2026 | The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service. | |
| Modificada | Media (5) | 67% | 💥 Exploit | Code-crafters Ability Server | 22/10/2004 | 16/6/2026 | Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Code-crafters Ability Server | 22/10/2004 | 16/6/2026 | Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command. | |
| Modificada | Media (4.6) | 0.42% | — | Robert Hyatt Crafty | 29/3/2004 | 16/6/2026 | Multiple buffer overflows in main.c for Crafty 19.3 allow local users to gain group "games" privileges via long command line arguments to crafty.bin. | |
| Modificada | Media (5) | 1.9% | — | Jcraft Jzlib | 31/12/2002 | 16/6/2026 | InfBlocks.java in JCraft JZlib before 0.0.7 allow remote attackers to cause a denial of service (NullPointerException) via an invalid block of deflated data. |