Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Ultravnc Repeater | 25/8/2016 | 17/6/2026 | UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in between the IP address and port number. | |
| Modificada | Media (6.5) | 1.0% | — | Amazonbasics FirmwareDell Km714 FirmwareDell Km632 FirmwareLogitech Unifying Firmware+1 | 2/8/2016 | 17/6/2026 | The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity… | |
| Modificada | Alta (7.5) | 2.3% | — | Usersultra | 9/6/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) data_target or (2) data_vote parameter in a rating_vote (wp_ajax_nopriv_rating_vote) action to wp-admin/admin-ajax.php. | |
| Modificada | Baja (3.7) | 74% | — | Oracle Communications Application Session ControllerOracle Communications Policy ManagementOracle Http ServerOracle Integrated Lights OUT Manager Firmware+57 | 1/4/2015 | 17/6/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally… | |
| Modificada | Media (4.3) | 1.5% | — | Ultrapop I-httpd | 12/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP header, a different vulnerability than CVE-2014-7261. | |
| Modificada | Media (4.3) | 1.8% | — | Ultrapop I-httpd | 12/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Omake BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string. | |
| Modificada | Media (4.3) | 1.1% | — | Ultrapop I-httpd | 12/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string that is improperly rendered during construction of a directory index page, a different vulnerability than CVE-2014-7263. | |
| Modificada | Alta (7.5) | 2.1% | — | Ultrapop I-httpd | 12/12/2014 | 17/6/2026 | The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to execute arbitrary commands by uploading files containing commands in SSI directives. | |
| Modificada | Baja (3.5) | 1.7% | 💥 Exploit | Yealink Gigabit Color IP Phone Sip-t32gYealink Gigabit Color IP Phone Sip-t38gYealink IP Phone Sip-t19pYealink IP Phone Sip-t20p+10 | 17/9/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com. | |
| Modificada | Baja (3.5) | 1.8% | — | HP Autonomy Ultraseek | 21/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in HP Autonomy Ultraseek 5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 64% | 💥 Exploit | Vector Ultra Mini Httpd | 31/7/2013 | 16/6/2026 | Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP request. | |
| Modificada | Media (6.9) | 0.40% | — | Ezbsystems Ultraiso | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in UltraISO 9.3.6.2750 allows local users to gain privileges via a Trojan horse daemon.dll file in the current working directory, as demonstrated by a directory that contains a .iso file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.9) | 0.40% | — | Ultravnc | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in UltraVNC 1.0.8.2 allows local users to gain privileges via a Trojan horse vnclang.dll file in the current working directory, as demonstrated by a directory that contains a .vnc file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 4.2% | — | Ultraedit | 16/9/2010 | 16/6/2026 | Untrusted search path vulnerability in IDM Computer Solutions UltraEdit 16.20.0.1009, 16.10.0.1036, and probably other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a bin, cpp,… | |
| Modificada | Alta (7.5) | 1.0% | — | Thomas Hempel TH Ultracards | 22/7/2010 | 16/6/2026 | SQL injection vulnerability in the ultraCards (th_ultracards) extension before 0.5.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (9.3) | 5.8% | 💥 Exploit | Ultraplayer Media Player | 11/5/2010 | 16/6/2026 | Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a .usk file. | |
| Modificada | Media (4.3) | 0.84% | — | Yourfreeworld Ultra Classifieds PRO | 2/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in listads.php in YourFreeWorld Ultra Classifieds Pro allows remote attackers to inject arbitrary web script or HTML via the cn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Yourfreeworld Ultra Classifieds PRO | 2/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php. | |
| Modificada | Alta (9.3) | 4.9% | 💥 Exploit | Tricerasoft Swift Ultralite | 18/9/2009 | 16/6/2026 | Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file. | |
| Modificada | Alta (9.3) | 2.7% | 💥 Exploit | Ultrafunk Popcorn | 15/5/2009 | 16/6/2026 | Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a long string in a +OK response. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 43% | 💥 Exploit | Ezbsystems Ultraiso | 7/4/2009 | 16/6/2026 | Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file. | |
| Modificada | Alta (9.3) | 3.0% | — | Ezbsystems Ultraiso | 1/4/2009 | 16/6/2026 | Multiple buffer overflows in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via a crafted (1) CIF, (2) C2D, or (3) GI file. | |
| Modificada | Alta (9.3) | 2.5% | — | Ezbsystems Ultraiso | 1/4/2009 | 16/6/2026 | Multiple format string vulnerabilities in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via format string specifiers in the filename of a (1) DAA or (2) ISZ file. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ultrastats | 24/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | TightvncUltravnc | 4/2/2009 | 16/6/2026 | Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b)… |