Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.2%—F-secure Anti-virusF-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR Citrix Servers+1015/4/201016/6/2026
F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier,…
ModificadaMedia (5)21%—Microsoft Windows 2000Microsoft Windows XPMicrosoft Windows 2003 ServerMicrosoft Windows Server 2003+214/4/201016/6/2026
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and…
ModificadaMedia (5)11%—Microsoft Windows 2000Microsoft Windows XPMicrosoft Windows 2003 ServerMicrosoft Windows Server 2003+214/4/201016/6/2026
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka…
ModificadaMedia (4.3)1.1%—Phpscriptsnow Real Time Currency Exchange15/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in rates.php in Real Time Currency Exchange allows remote attackers to inject arbitrary web script or HTML via the Amount parameter.
ModificadaMedia (4.3)1.1%—Ljscripts Auto-surf Traffic Exchange Script30/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary web script or HTML via the rid parameter to (1) index.php, (2) faq.php, and (3) register.php.
ModificadaAlta (7.5)1.1%—Melvin Mach Jobexchange17/12/200916/6/2026
SQL injection vulnerability in the Job Exchange (jobexchange) extension 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (5)2.6%—Sophos Puremessage FOR Microsoft Exchange27/8/200916/6/2026
The installation of Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2, when both anti-virus and anti-spam are supported, does not create or launch the associated scan engines when the system is under heavy load, which has unspecified impact, probably remote bypass of scanner protection or a denial of service…
ModificadaMedia (5)3.3%—Sophos Puremessage FOR Microsoft Exchange27/8/200916/6/2026
Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (EdgeTransport.exe termination) via a TNEF-encoded message with a crafted rich text body that is not properly handled during conversion to plain text. NOTE: this might be related to CVE-2008-7104.
ModificadaMedia (5)3.3%—Sophos Puremessage FOR Microsoft Exchange27/8/200916/6/2026
Sophos PureMessage Scanner service (PMScanner.exe) in PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (message queue delay and incomplete spam rule update) via a crafted (1) RTF or (2) PDF file.
ModificadaAlta (10)3.7%💥 ExploitSkalinks Exchange Script19/8/200916/6/2026
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/register.php.
ModificadaAlta (7.5)2.8%💥 ExploitBlogtrafficexchange Related-sites8/7/200916/6/2026
SQL injection vulnerability in BTE_RW_webajax.php in the Related Sites plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the guid parameter.
ModificadaMedia (4.3)1.2%💥 ExploitDavid Degner Phpcollegeexchange25/6/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in phpCollegeExchange 0.1.5c allow remote attackers to inject arbitrary web script or HTML via the (1) _SESSION[handle] parameter to (a) home.php, (b) books/allbooks.php, or (c) books/home.php; or the (2) home parameter to (d) i_head.php or (e) i_nav.php, or (f)…
ModificadaMedia (6.8)1.6%💥 ExploitDavid Degner Phpcollegeexchange25/6/200916/6/2026
Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the home parameter to (1) i_head.php, (2) i_nav.php, (3) user_new_2.php, or (4) house/myrents.php; or (5) allbooks.php, (6) home.php, or…
ModificadaAlta (7.5)0.97%💥 ExploitDavid Degner Phpcollegeexchange17/6/200916/6/2026
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute arbitrary SQL commands via the itemnr parameter.
ModificadaAlta (7.5)0.97%💥 Exploit1scripts Z1exchange2/3/200916/6/2026
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.5%💥 Exploit1scripts Z1exchange2/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)3.1%💥 ExploitAdserversolutions Banner Exchange Software2/3/200916/6/2026
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL commands via the (1) username (uname parameter) and (2) password (pass parameter). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.97%💥 Exploit1scripts Z1exchange25/2/200916/6/2026
SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via the site parameter.
ModificadaMedia (5)26%—Microsoft Exchange Server10/2/200916/6/2026
The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing…
ModificadaAlta (9.3)25%—Microsoft Exchange Server10/2/200916/6/2026
Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
ModificadaAlta (7.5)1.2%💥 ExploitEzonescripts Adult Banner Exchange Website10/2/200916/6/2026
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
ModificadaAlta (7.6)5.5%—F-secure Anti-virusF-secure Anti-virus FOR Citrix ServersF-secure Anti-virus FOR Microsoft ExchangeF-secure Anti-virus FOR Mimesweeper+136/2/200916/6/2026
Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer…
ModificadaMedia (4.3)48%💥 ExploitMicrosoft Exchange Server21/10/200816/6/2026
Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
ModificadaAlta (7.5)1.2%💥 ExploitAlstrasoft Forum PAY PER Post Exchange11/9/200816/6/2026
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showcat action.
ModificadaAlta (7.5)0.99%💥 ExploitYourfreeworld Ad-exchange Script21/8/200816/6/2026
SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Orbitaley — Vulnerabilidades