Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 11% | — | Broadcom Total Defense | 18/4/2011 | 16/6/2026 | Directory traversal vulnerability in the Heartbeat Web Service in CA.Itm.Server.ManagementWS.dll in the Management Server in CA Total Defense (TD) r12 before SE2 allows remote attackers to execute arbitrary code via directory traversal sequences in the GUID parameter in an upload request to FileUploadHandler.ashx. | |
| Modificada | Alta (10) | 89% | 💥 Exploit | Broadcom Total Defense | 18/4/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2) UnassignAdminRoles, (3) DeleteFilter, (4) NonAssignedUserList, (5)… | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Sweetphp Totalcalendar | 28/7/2010 | 16/6/2026 | Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the box parameter. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Sweetphp Totalcalendar | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Sweetphp Totalcalender | 12/7/2010 | 16/6/2026 | admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters. | |
| Modificada | Alta (7.5) | 1.3% | — | Sweetphp Totalcalendar | 12/7/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922 and CVE-2006-7055. | |
| Modificada | Alta (7.2) | 0.70% | 💥 Exploit | Quickheal Antivirus Plus 2009Quickheal Total Security 2009 | 4/1/2010 | 16/6/2026 | Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe. | |
| Modificada | Media (4.3) | 2.4% | — | Broadcom Anti-virusBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti-virus SDKBroadcom Common Services+29 | 13/10/2009 | 16/6/2026 | Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to… | |
| Modificada | Alta (9.3) | 7.6% | — | Broadcom Anti-virusBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti-virus SDKBroadcom Common Services+28 | 13/10/2009 | 16/6/2026 | Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to… | |
| Modificada | Alta (7.6) | 2.8% | — | Mcafee Active Virus DefenseMcafee Active VirusscanMcafee Email GatewayMcafee Internet Security Suite+9 | 30/4/2009 | 16/6/2026 | The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Sweetphp Totalcalendar | 24/4/2009 | 16/6/2026 | Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the include parameter. | |
| Modificada | Alta (7.2) | 0.58% | — | Gdata Antivirus 2008Gdata Internetsecurity 2008Gdata Totalcare 2008 | 28/1/2009 | 16/6/2026 | The GDTdiIcpt.sys driver in G DATA AntiVirus 2008, InternetSecurity 2008, and TotalCare 2008 populates kernel registers with IOCTL 0x8317001c input values, which allows local users to cause a denial of service (system crash) or gain privileges via a crafted IOCTL request, as demonstrated by execution of the KeSetEvent… | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | Effectmatrix Total Video Player | 23/1/2009 | 16/6/2026 | Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value. | |
| Modificada | Alta (9.3) | 5.7% | — | Clientsoftware Wincom MPD Total | 20/11/2008 | 16/6/2026 | Multiple buffer overflows in Client Software WinCom LPD Total 3.0.2.623 and earlier allow remote attackers to execute arbitrary code via (1) a long 0x02 command to the remote administration service on TCP port 13500 or (2) a long invalid control filename to LPDService.exe on TCP port 515. | |
| Modificada | Alta (10) | 60% | 💥 Exploit | Clientsoftware Wincome MPD Total | 18/11/2008 | 16/6/2026 | Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to cause a denial of service (crash) via a large string length argument, which triggers memory corruption. | |
| Modificada | Alta (7.5) | 1.8% | — | Clientsoftware Wincome MPD Total | 18/11/2008 | 16/6/2026 | Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to bypass authentication and perform administrative actions via vectors involving "simply skipping the auth stage." | |
| Modificada | Media (4.3) | 1.3% | — | Telartis BV Awstats Totals | 4/9/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter. | |
| Modificada | Alta (9.3) | 53% | 💥 Exploit | Telartis BV Awstats Totals | 4/9/2008 | 16/6/2026 | awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function. | |
| Modificada | Media (4.3) | 5.7% | 💥 Exploit | Totalplayer | 28/12/2007 | 16/6/2026 | TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. NOTE: this might be a duplicate of CVE-2006-6288. | |
| Modificada | Crítica (9.8) | 27% | 💥 Exploit | Bitdefender AntivirusBitdefender Internet SecurityBitdefender Total Security | 1/11/2007 | 16/6/2026 | Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for… | |
| Modificada | Media (6.8) | 3.6% | — | Ghisler Total Commander | 8/9/2007 | 16/6/2026 | Directory traversal vulnerability in the FTP client in Total Commander before 7.02 allows remote FTP servers to create or overwrite arbitrary files via "..\" (dot dot backslash) sequences in a filename. NOTE: the "..\" are not displayed when the user lists files. NOTE: this can be leveraged for code execution by… | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Fransois Gannier Fileinfo PluginGhisler Total Commander | 21/8/2007 | 16/6/2026 | The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer in (1) an IMAGE_THUNK_DATA structure, involving the (a) OriginalFirstThunk and (b) FirstThunk IMAGE_IMPORT_DESCRIPTOR fields, or (2) the… | |
| Modificada | Media (4.3) | 1.2% | — | Fransois Gannier Fileinfo PluginGhisler Total Commander | 21/8/2007 | 16/6/2026 | CRLF injection vulnerability in the Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to spoof the information in the Image File Header tab via strings with CRLF sequences in the IMAGE_EXPORT_DIRECTORY array in a PE file, which could complicate forensics investigations. | |
| Modificada | Alta (10) | 1.8% | 💥 Exploit | Sweetphp Totalcalendar | 3/7/2007 | 16/6/2026 | SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 3.3% | — | IBM Totalstorage Ds400 | 15/6/2007 | 16/6/2026 | The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000. |