Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

388 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.00%💥 ExploitVastal I-tech Dating Zone7/10/200816/6/2026
SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote attackers to execute arbitrary SQL commands via the fage parameter.
ModificadaAlta (7.5)0.97%💥 ExploitVastal I-tech Mmorpg Zone7/10/200816/6/2026
SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the game_id parameter.
ModificadaAlta (7.5)5.6%💥 ExploitVastal Phpvid22/9/200816/6/2026
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610. NOTE: it was later reported that 1.2.3 is also affected.
ModificadaAlta (7.5)1.0%💥 ExploitVastal Shaadi Zone11/9/200816/6/2026
SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to execute arbitrary SQL commands via the tage parameter.
ModificadaAlta (7.5)1.1%💥 ExploitVastal Agent Zone11/9/200816/6/2026
SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter.
ModificadaMedia (4.4)0.28%—Checkinstall1/7/200816/6/2026
Race condition in (1) checkinstall 1.6.1 and (2) installwatch allows local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on temporary working directories.
ModificadaAlta (9.3)8.5%—Microsoft Windows Installer4/6/200816/6/2026
Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if msiexec.exe is reachable via components…
ModificadaMedia (4.3)4.0%💥 ExploitVastal Phpvid19/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 1.2.3 is also affected.
AnalizadaAlta (9.3)2.2%—Revenera Installshield4/4/200816/6/2026
The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine.
ModificadaAlta (7.5)4.6%💥 ExploitSejoong Namo ActivesquareSejoong Namo Namoinstall.1 Activex Control6/2/200816/6/2026
Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.
ModificadaAlta (9.3)8.6%💥 ExploitBusinessobjects Crystal Reports XI22/1/200816/6/2026
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow.
ModificadaAlta (9.3)37%💥 ExploitMacrovision Flexnet ConnectMacrovision Installshield 2008Macrovision Update Service2/11/200716/6/2026
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.
ModificadaMedia (6.8)3.8%💥 ExploitCrystal Reality LLC Crystalplayer PRO27/7/200716/6/2026
Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long string in a .mls Playlist file.
ModificadaAlta (7.5)1.2%💥 ExploitVastal I-tech Phpvid6/7/200716/6/2026
SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
ModificadaAlta (7.5)1.0%💥 ExploitVastal I-tech Buddy Zone3/7/200716/6/2026
SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
ModificadaMedia (4.3)1.8%💥 ExploitOracle Application ServerOracle Rapid Install WEB Server3/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the…
ModificadaAlta (7.5)2.5%💥 ExploitVastal I-tech Buddy Zone3/7/200716/6/2026
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php.
ModificadaMedia (4.3)16%💥 ExploitMicrosoft Internet ExplorerStalker Communigate PRO16/5/200716/6/2026
Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags.
ModificadaMedia (4.6)0.32%—Macrovision Installanywhere19/4/200716/6/2026
Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification…
ModificadaAlta (9.3)5.4%—Macrovision Installfromtheweb23/2/200716/6/2026
Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents.
ModificadaMedia (4.6)0.36%—Barron Mccann InstallBarron Mccann X-kryptor DriverBarron Mccann X-kryptor Secure ClientBarron Mccann Xgntr4/2/200716/6/2026
Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.
ModificadaAlta (7.6)18%💥 ExploitApple InstallerApple MAC OS X31/1/200716/6/2026
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.
ModificadaBaja (1.9)0.42%—Thomas Lange Fully Automated InstallationDebian Linux18/12/200616/6/2026
The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows attackers to obtain the hash.
ModificadaAlta (7.5)1.7%—Businessobjects Crystal Enterprise29/11/200616/6/2026
Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of other users via WCSID cookie values.
ModificadaAlta (7.6)52%💥 ExploitBusinessobjects Crystal Reports XIMicrosoft Visual Studio .net28/11/200616/6/2026
Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
Orbitaley — Vulnerabilidades