Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.6% | — | Gvectors Wpforo | 28/5/2018 | 17/6/2026 | The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. | |
| Modificada | Alta (7.8) | 0.33% | — | Bj-tct Kingview | 25/2/2018 | 17/6/2026 | KingView 7.5SP1 has an integer overflow during stgopenstorage API read operations. | |
| Modificada | Media (6.8) | 0.66% | — | Iodata Hdl-xr FirmwareIodata Hdl-xrw FirmwareIodata Hdl-xr2u FirmwareIodata Hdl-xr2uw Firmware+41 | 8/2/2018 | 17/6/2026 | Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.60% | — | Tomaxcom R60g FirmwareTomaxcom R60gv2 Firmware | 18/8/2017 | 17/6/2026 | ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack. | |
| Modificada | Alta (7.8) | 3.1% | 💥 Exploit | Halliburton Logview PRO | 15/5/2017 | 17/6/2026 | Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file. | |
| Modificada | Media (6.1) | 0.96% | — | Nagvis | 2/3/2017 | 17/6/2026 | An issue was discovered in NagVis 1.9b12. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | |
| Modificada | Media (6.5) | 2.5% | — | Netgear Fvs336gv3 FirmwareNetgear Srx5308 FirmwareNetgear Fvs318gv2 FirmwareNetgear Fvs318n Firmware | 3/1/2017 | 17/6/2026 | Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file. | |
| Modificada | Media (6.4) | 1.4% | — | SAP Netweaver Logviewer | 20/11/2013 | 17/6/2026 | SAP NetWeaver Logviewer 6.30, when running on Windows, allows remote attackers to bypass intended access restrictions via unspecified vectors. | |
| Modificada | Media (5.8) | 2.6% | 💥 Exploit | Wellintech Kingview | 25/10/2013 | 17/6/2026 | The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveToFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the single pathname argument,… | |
| Modificada | Media (5.8) | 14% | 💥 Exploit | Wellintech Kingview | 25/10/2013 | 16/6/2026 | The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict ReplaceDBFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the two pathname… | |
| Modificada | Alta (10) | 61% | 💥 Exploit | Wellintech Kingview | 15/2/2013 | 16/6/2026 | Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted packet. | |
| Modificada | Baja (2.1) | 0.32% | — | Wellintech Kingview | 10/10/2012 | 16/6/2026 | WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials by reading an unspecified file. | |
| Modificada | Media (5) | 2.6% | — | Wellintech Kingview | 5/7/2012 | 16/6/2026 | Directory traversal vulnerability in WellinTech KingView 6.53 allows remote attackers to read arbitrary files via a crafted HTTP request to port 8001. | |
| Modificada | Alta (10) | 5.9% | — | Wellintech Kingview | 5/7/2012 | 16/6/2026 | WellinTech KingView 6.53 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted packet to (1) TCP or (2) UDP port 2001. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Wellintech Kingview | 5/7/2012 | 16/6/2026 | Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555. | |
| Modificada | Alta (10) | 7.7% | 💥 Exploit | Wellintech Kingview | 5/7/2012 | 16/6/2026 | Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555. | |
| Modificada | Alta (7.1) | 0.79% | — | Wellintech Kingview | 9/5/2012 | 16/6/2026 | WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file. | |
| Modificada | Alta (9.3) | 1.7% | — | Wellintech Kingview | 2/5/2012 | 16/6/2026 | Untrusted search path vulnerability in WellinTech KingView 6.53 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Alta (10) | 8.5% | — | Wellintech Kingview | 27/12/2011 | 16/6/2026 | Heap-based buffer overflow in nettransdll.dll in HistorySvr.exe (aka HistoryServer.exe) in WellinTech KingView 6.53 and 65.30.2010.18018 allows remote attackers to execute arbitrary code via a crafted op-code 3 packet. | |
| Modificada | Alta (10) | 38% | 💥 Exploit | Wellintech Kingview | 16/8/2011 | 16/6/2026 | Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arbitrary code via a long second argument to the ValidateUser method. | |
| Modificada | Alta (10) | 21% | 💥 Exploit | Wellintech Kingview | 11/1/2011 | 16/6/2026 | Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a long request to TCP port 777. | |
| Modificada | Alta (9.3) | 9.1% | — | Gvim | 3/11/2010 | 16/6/2026 | Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a… | |
| Modificada | Baja (3.3) | 0.33% | — | GNU GV | 22/7/2010 | 16/6/2026 | GNU gv before 3.7.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | |
| Modificada | Alta (10) | 2.6% | — | Linksys Wap54gv3 | 10/6/2010 | 16/6/2026 | Linksys WAP54Gv3 firmware 3.04.03 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) data2 and (2) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi. | |
| Modificada | Media (4.3) | 0.84% | — | Steffen Kamper Reports Logview | 19/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Reports Logfile View (reports_logview) extension 1.2.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |