Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—Coronamatrix Phpaddressbook7/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in CoronaMatrix phpAddressBook 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
ModificadaAlta (7.8)5.7%💥 ExploitPrecisionid Data Matrix Barcode Activex Control1/4/200916/6/2026
Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datamatrix) allow remote attackers to overwrite arbitrary files via the (1) SaveBarCode and (2) SaveEnhWMF methods.
ModificadaAlta (9.3)13%💥 ExploitEffectmatrix Total Video Player23/1/200916/6/2026
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value.
ModificadaAlta (7.5)1.0%💥 ExploitActivewebsoftwares Active Force Matrix17/12/200816/6/2026
SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9)7.1%💥 ExploitMW6 Technologies Datamatrix Activex4/11/200816/6/2026
Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, DataMatrix.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.
ModificadaAlta (7.5)1.3%—Yourfreeworld Forced Matrix Script21/8/200816/6/2026
SQL injection vulnerability in tr1.php in YourFreeWorld Forced Matrix Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (9.3)6.0%💥 ExploitIdautomation Aztec BarcodeIdautomation Datamatrix BarcodeIdautomation Linear BarcodeIdautomation Pdf417 Barcode18/5/200816/6/2026
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL…
ModificadaAlta (7.5)0.97%💥 ExploitCoronamatrix Phpaddressbook16/4/200816/6/2026
SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)3.2%💥 ExploitCoronamatrix Phpaddressbook25/3/200816/6/2026
Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php and (2) install.php. NOTE: it was later reported that vector 1 is also present in 2.0.
ModificadaAlta (7.5)12%💥 ExploitInmatrix Zoom Player27/12/200716/6/2026
Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file in a crafted ZPL file, which causes an overflow in Unicode handling when generating an error message.
ModificadaMedia (6.8)1.3%—Squiz Mysource ClassicSquiz Mysource Matrix27/9/200616/6/2026
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not…
ModificadaMedia (6.8)1.3%—Squiz Mysource Matrix27/9/200616/6/2026
MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider…
ModificadaMedia (4.3)1.2%—Orbitcoders Orbitmatrix18/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to inject arbitrary web script or HTML via the page_name parameter with an IMG tag containing a javascript URI in the SRC attribute.
ModificadaMedia (5)1.2%—Orbitcoders Orbitmatrix18/7/200616/6/2026
index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to obtain sensitive information (partial database schema) via a modified page_name parameter, which reflects portions of an SQL query in the result. NOTE: it is not clear whether the information is target-specific. If not, then this issue is not an…
ModificadaAlta (7.5)1.2%—Orbitcoders Orbitmatrix18/7/200616/6/2026
index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to trigger a SQL error via the page_name parameter, possibly due to a SQL injection vulnerability.
ModificadaAlta (7.5)1.2%—Peersec Networks Matrixssl31/12/200416/6/2026
PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session.
ModificadaMedia (5.8)0.79%—Peersec Networks Matrixssl31/12/200416/6/2026
PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms…
ModificadaMedia (5)1.8%—Matrix FTP ServerAI6/2/200416/6/2026
Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.
ModificadaMedia (5)2.6%—Matrixs CGI Vault Last Lines30/12/200116/6/2026
Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable.
ModificadaAlta (7.5)1.9%—Matrixs CGI Vault Last Lines30/12/200116/6/2026
Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable.
ModificadaMedia (4.6)0.41%—Macromedia Matrix Screen Saver4/10/199916/6/2026
Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.