Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 4.0% | 💥 Exploit | Grandstream Budgetone 200 | 21/3/2007 | 16/6/2026 | El teléfono IP Grandstream BudgeTone 200, con el programa 1.1.1.14 y el cargador de arranque 1.1.1.5, permite a atacantes remotos provocar una denegación de servicio (caída del dispositivo) mediante mensajes SIP (1) INVITE, (2) CANCEL, y otros no especificados con una cabecera WWW-Authenticate que contiene un dominio… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Nicolas Grandjean Phpmyring | 3/2/2007 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en lang/leslangues.php de Nicolas Grandjean PHPMyRing 4.1.3b y versiones anteriores permite a atacantes remotos ejecutar código PHP de su elección a través del parámetro fichier. | |
| Modificada | Alta (7.5) | 1.5% | — | Scriptsez Random PHP Quote | 26/1/2007 | 16/6/2026 | Scriptsez Random PHP Quote 1.0 almacena información sensible bajo la raíz web con control de acceso insuficiente, lo cual permite a atacantes remotos obtener información de contraseñas mediante una petición directa de pwd.txt. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Grandora Rialto | 13/1/2007 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Rialto 1.6 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) cat en (a) listmain.asp o (b) searchmain.asp, el parámetro (2) Keyword en (c) searchkey.asp, o el parámetro (3) refon en (d)… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Grandora Rialto | 13/1/2007 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en Rialto 1.6 permite a atacantes remotos ejecutar comandos SQL a través de los campos (1) unam (nombre de usuario) y (2)pword (contraseña) en (a) admin/default.asp; el parámetro (4) cat en (d) listmain.asp, (e) searchoption.asp, o (f) searchmain.asp; el parámetro (5)… | |
| Modificada | Alta (7.8) | 2.1% | — | Grandstream Gxp-2000 | 11/10/2006 | 16/6/2026 | Grandstream GXP-2000 VoIP Desktop Phone, versión del firmware 1.1.0.5, permite a atacantes remotos provocar una denegación de servicio (cuelgue o reinicio) mediante una gran cantidad de información ASCII enviada al puerto (1) 5060/UDP, (2) 5062/UDP, (3) 5064/UDP, (4) 5066/UDP, (5) 9876/UDP, o (6) 26789/UDP. | |
| Modificada | Alta (7.5) | 2.0% | — | Randshop | 12/7/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en Randshop anterior a la 1.2 permite a atacantes remotos ejecutar código PHP de su elección mediante el parámetro dateiPfad, un vector distinto de CVE-2006-3375. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Randshop | 6/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attackers to execute arbitrary PHP code via a URL in the incl parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Randshop | 6/7/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivos en PHP en includes/header.inc.php en Randshop v1.1.1 permite a atacantes remotos ejecutar código PHP de su eleccio´n a través del parámetro dateiPfad. | |
| Modificada | Media (5) | 1.4% | — | Random Mouse Software RED Queen | 20/12/2005 | 16/6/2026 | redqueen.cgi in Red Queen 1.02 and earlier allows remote attackers to obtain the full server path via invalid (1) yellowpage_id, (2) skin_id, (3) supplier_id, and (4) module parameters, which leaks the path in an error message. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Randshop | 30/11/2005 | 16/6/2026 | SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Grandstream Budgetone 101Grandstream Budgetone 102 | 16/8/2005 | 16/6/2026 | Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (device hang or reboot) via a large UDP packet to port 5060. | |
| Modificada | Alta (7.5) | 1.2% | — | Grandstream Bt-100 Firmware | 11/7/2005 | 16/6/2026 | Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message. | |
| Modificada | Alta (7.5) | 3.7% | — | Popup Plus Plugin FOR Miranda IM | 2/5/2005 | 16/6/2026 | Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code. | |
| Modificada | Media (4.6) | 0.56% | 💥 Exploit | Rebrand P2P Share SPY | 2/5/2005 | 16/6/2026 | Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges. | |
| Modificada | Alta (7.5) | 3.7% | — | Denis Sbragion SredirdPeter Astrand Sercd | 31/12/2004 | 16/6/2026 | Buffer overflow in the HandleCPCCommand function of sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 3.2% | — | Denis Sbragion SredirdPeter Astrand Sercd | 31/12/2004 | 16/6/2026 | Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function. | |
| Modificada | Baja (2.1) | 0.35% | — | Fortres Grand Corporation Fortres | 31/12/2002 | 16/6/2026 | Fortres 101 4.1 allows local users to bypass Fortres by pressing the Windows and "F" key together for 30 seconds, which opens multiple windows and eventually causes explorer.exe to crash, which then opens an unrestricted explorer.exe. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Randy Parker Power UP Html | 7/9/2001 | 16/6/2026 | Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter. |