Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Vastal I-tech Dating Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote attackers to execute arbitrary SQL commands via the fage parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Vastal I-tech Mmorpg Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the game_id parameter. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Vastal Phpvid | 22/9/2008 | 16/6/2026 | SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610. NOTE: it was later reported that 1.2.3 is also affected. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal Shaadi Zone | 11/9/2008 | 16/6/2026 | SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to execute arbitrary SQL commands via the tage parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Vastal Agent Zone | 11/9/2008 | 16/6/2026 | SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter. | |
| Modificada | Media (4.4) | 0.28% | — | Checkinstall | 1/7/2008 | 16/6/2026 | Race condition in (1) checkinstall 1.6.1 and (2) installwatch allows local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on temporary working directories. | |
| Modificada | Alta (9.3) | 8.5% | — | Microsoft Windows Installer | 4/6/2008 | 16/6/2026 | Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if msiexec.exe is reachable via components… | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Vastal Phpvid | 19/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 1.2.3 is also affected. | |
| Analizada | Alta (9.3) | 2.2% | — | Revenera Installshield | 4/4/2008 | 16/6/2026 | The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Sejoong Namo ActivesquareSejoong Namo Namoinstall.1 Activex Control | 6/2/2008 | 16/6/2026 | Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551. | |
| Modificada | Alta (9.3) | 8.6% | 💥 Exploit | Businessobjects Crystal Reports XI | 22/1/2008 | 16/6/2026 | Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow. | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Macrovision Flexnet ConnectMacrovision Installshield 2008Macrovision Update Service | 2/11/2007 | 16/6/2026 | Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow. | |
| Modificada | Media (6.8) | 3.8% | 💥 Exploit | Crystal Reality LLC Crystalplayer PRO | 27/7/2007 | 16/6/2026 | Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long string in a .mls Playlist file. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Vastal I-tech Phpvid | 6/7/2007 | 16/6/2026 | SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Vastal I-tech Buddy Zone | 3/7/2007 | 16/6/2026 | SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Oracle Application ServerOracle Rapid Install WEB Server | 3/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Vastal I-tech Buddy Zone | 3/7/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php. | |
| Modificada | Media (4.3) | 16% | 💥 Exploit | Microsoft Internet ExplorerStalker Communigate PRO | 16/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags. | |
| Modificada | Media (4.6) | 0.32% | — | Macrovision Installanywhere | 19/4/2007 | 16/6/2026 | Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification… | |
| Modificada | Alta (9.3) | 5.4% | — | Macrovision Installfromtheweb | 23/2/2007 | 16/6/2026 | Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents. | |
| Modificada | Media (4.6) | 0.36% | — | Barron Mccann InstallBarron Mccann X-kryptor DriverBarron Mccann X-kryptor Secure ClientBarron Mccann Xgntr | 4/2/2007 | 16/6/2026 | Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer. | |
| Modificada | Alta (7.6) | 18% | 💥 Exploit | Apple InstallerApple MAC OS X | 31/1/2007 | 16/6/2026 | Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename. | |
| Modificada | Baja (1.9) | 0.42% | — | Thomas Lange Fully Automated InstallationDebian Linux | 18/12/2006 | 16/6/2026 | The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows attackers to obtain the hash. | |
| Modificada | Alta (7.5) | 1.7% | — | Businessobjects Crystal Enterprise | 29/11/2006 | 16/6/2026 | Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of other users via WCSID cookie values. | |
| Modificada | Alta (7.6) | 52% | 💥 Exploit | Businessobjects Crystal Reports XIMicrosoft Visual Studio .net | 28/11/2006 | 16/6/2026 | Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file. |