Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

525 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)6.0%—Adobe Shockwave Player12/2/201417/6/2026
Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0500.
ModificadaAlta (10)5.9%—Adobe Shockwave Player12/2/201417/6/2026
Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0501.
ModificadaAlta (10)3.8%—Adobe Shockwave Player11/12/201316/6/2026
Adobe Shockwave Player before 12.0.7.148 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5333.
ModificadaAlta (10)3.8%—Adobe Shockwave Player11/12/201316/6/2026
Adobe Shockwave Player before 12.0.7.148 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5334.
ModificadaMedia (6.8)10%💥 ExploitKTH Snack Sound ToolkitKTH WavesurferOpensuse28/10/201316/6/2026
Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.
ModificadaAlta (10)4.6%—Adobe Shockwave Player12/9/201316/6/2026
Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3359.
ModificadaAlta (10)3.8%—Adobe Shockwave Player12/9/201316/6/2026
Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3360.
ModificadaAlta (9)2.5%—Wave Embassy Remote Administration ServerWave Embassy Remote Administration Server Help Desk15/7/201316/6/2026
SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field), leading to execution of operating-system commands.
ModificadaAlta (7.5)1.3%—Wave Embassy Remote Administration ServerWave Embassy Remote Administration Server Help Desk15/7/201316/6/2026
SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote attackers to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field).
ModificadaMedia (5)14%💥 ExploitTrustwave ModsecurityOpensuse15/7/201316/6/2026
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
ModificadaAlta (10)3.8%—Adobe Shockwave Player10/7/201316/6/2026
Adobe Shockwave Player before 12.0.3.133 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
ModificadaAlta (7.5)4.2%—Trustwave ModsecurityOpensuseFedoraproject FedoraDebian Linux25/4/201316/6/2026
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.
ModificadaAlta (10)3.9%—Adobe Shockwave Player10/4/201316/6/2026
Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-1384.
ModificadaAlta (10)4.3%—Adobe Shockwave Player10/4/201316/6/2026
Adobe Shockwave Player before 12.0.2.122 does not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.
ModificadaAlta (10)3.9%—Adobe Shockwave Player10/4/201316/6/2026
Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-1386.
ModificadaAlta (10)6.0%—Adobe Shockwave Player10/4/201316/6/2026
Buffer overflow in Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (10)9.3%—Adobe Shockwave Player13/2/201316/6/2026
Stack-based buffer overflow in Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (10)5.3%—Adobe Shockwave Player13/2/201316/6/2026
Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
ModificadaMedia (5)13%💥 ExploitTrustwave ModsecurityOpensuseFedoraproject Fedora28/12/201216/6/2026
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
ModificadaAlta (9.3)2.7%—Adobe Shockwave Player20/12/201216/6/2026
Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of arbitrary signed Xtras via a Shockwave movie that contains an Xtra URL, as demonstrated by a URL for an outdated Xtra.
ModificadaAlta (9.3)2.5%—Adobe Shockwave Player20/12/201216/6/2026
Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of a Shockwave Player 10.4.0.025 compatibility feature via a crafted HTML document that references Shockwave content with a certain compatibility parameter, related to a "downgrading" attack.
ModificadaMedia (5)1.3%—Longwaveconsulting Ubercart Securetrading Payment Method Module31/10/201216/6/2026
The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors.
ModificadaAlta (10)8.6%—Adobe Shockwave Player23/10/201216/6/2026
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-4175.
ModificadaAlta (10)7.3%—Adobe Shockwave Player23/10/201216/6/2026
Array index error in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (10)9.6%—Adobe Shockwave Player23/10/201216/6/2026
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-5273.
Orbitaley — Vulnerabilidades