Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
362 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 10% | 💥 Exploit | Microfocus Visibroker | 31/8/2009 | 16/6/2026 | Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet with a large string length value to UDP port 14000, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Focus-sis Focus SIS | 18/9/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in modules/Discipline/StudentFieldBreakdown.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter, a different vector than CVE-2007-4806. NOTE: the provenance of this information is unknown. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Focus SIS | 11/9/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Focus SIS | 11/9/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the staticpath parameter to (1) modules/Discipline/CategoryBreakdownTime.php or (2) modules/Discipline/StudentFieldBreakdown.php. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | KEY Focus KF WEB Server | 26/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | ECI Telecom B-focus Wireless 802.11bg Adsl2+ Router | 4/11/2006 | 16/6/2026 | ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI. | |
| Modificada | Alta (7.5) | 1.8% | — | ECI Telecom B-focus Router | 3/8/2005 | 16/6/2026 | B-FOCuS Router 312+ allows remote attackers to bypass authentication and gain unauthorized access via a direct request to firmwarecfg. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Liveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | KEY Focus KF WEB Server | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences. | |
| Modificada | Media (5) | 8.0% | 💥 Exploit | KEY Focus KF WEB Server | 4/10/2002 | 16/6/2026 | KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character. | |
| Modificada | Alta (7.5) | 2.3% | — | KEY Focus KF WEB Server | 4/10/2002 | 16/6/2026 | Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header. | |
| Modificada | Media (4.6) | 0.70% | 💥 Exploit | Microfocus Cobol | 2/6/2001 | 16/6/2026 | MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files. |