Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

362 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)10%💥 ExploitMicrofocus Visibroker31/8/200916/6/2026
Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet with a large string length value to UDP port 14000, which triggers a heap-based buffer overflow.
ModificadaAlta (7.5)2.3%💥 ExploitFocus-sis Focus SIS18/9/200716/6/2026
PHP remote file inclusion vulnerability in modules/Discipline/StudentFieldBreakdown.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter, a different vector than CVE-2007-4806. NOTE: the provenance of this information is unknown.
ModificadaAlta (7.5)3.2%💥 ExploitFocus SIS11/9/200716/6/2026
PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter.
ModificadaAlta (7.5)3.2%💥 ExploitFocus SIS11/9/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the staticpath parameter to (1) modules/Discipline/CategoryBreakdownTime.php or (2) modules/Discipline/StudentFieldBreakdown.php.
ModificadaMedia (4.3)2.4%💥 ExploitKEY Focus KF WEB Server26/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.
ModificadaMedia (5)3.3%💥 ExploitECI Telecom B-focus Wireless 802.11bg Adsl2+ Router4/11/200616/6/2026
ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI.
ModificadaAlta (7.5)1.8%—ECI Telecom B-focus Router3/8/200516/6/2026
B-FOCuS Router 312+ allows remote attackers to bypass authentication and gain unauthorized access via a direct request to firmwarecfg.
ModificadaMedia (4.3)1.7%💥 ExploitLiveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa.
ModificadaMedia (5)2.7%💥 ExploitKEY Focus KF WEB Server31/12/200216/6/2026
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
ModificadaMedia (5)8.0%💥 ExploitKEY Focus KF WEB Server4/10/200216/6/2026
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.
ModificadaAlta (7.5)2.3%—KEY Focus KF WEB Server4/10/200216/6/2026
Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header.
ModificadaMedia (4.6)0.70%💥 ExploitMicrofocus Cobol2/6/200116/6/2026
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
Orbitaley — Vulnerabilidades