Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)3.1%💥 ExploitSpaminator16/8/200616/6/2026
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
ModificadaAlta (7.8)53%💥 ExploitFilezilla Server Terminal16/11/200516/6/2026
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.
ModificadaAlta (7.5)25%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+314/6/200516/6/2026
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.
ModificadaMedia (5.1)13%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+314/6/200516/6/2026
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.
ModificadaAlta (7.4)16%💥 PoCMicrosoft Remote Desktop ConnectionMicrosoft Windows Terminal Services Using RDP1/6/200516/6/2026
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
ModificadaMedia (5)1.3%—Atari Terminator 3 WAR OF THE Machines31/5/200516/6/2026
Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a large nickname.
ModificadaMedia (5)1.9%—Atari Terminator 3 WAR OF THE Machines31/5/200516/6/2026
Buffer overflow in the client cd-key hash in Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a long client cd-key hash value, a different vulnerability than CVE-2005-1556.
ModificadaAlta (7.5)5.2%—Apple TerminalApple MAC OS X4/5/200516/6/2026
The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.
ModificadaMedia (5.1)3.1%—Apple TerminalApple MAC OS XApple MAC OS X Server4/5/200516/6/2026
Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.
ModificadaMedia (5)2.2%—Atari Terminator 3 WAR OF THE Machines19/3/200416/6/2026
Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo variable.
ModificadaAlta (7.2)4.6%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2000 Terminal Services18/8/200316/6/2026
Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
ModificadaMedia (4.6)2.2%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NTMicrosoft Windows XP12/5/200316/6/2026
Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
ModificadaAlta (7.5)37%💥 ExploitMicrosoft Virtual MachineMicrosoft Windows 2000Microsoft Windows 2000 Terminal Services5/5/200316/6/2026
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."
ModificadaMedia (5)38%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NTMicrosoft Windows XP2/4/200316/6/2026
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.
ModificadaAlta (7.5)86%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2000 Terminal Services31/3/200316/6/2026
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
ModificadaAlta (7.5)24%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 98Microsoft Windows 98se+324/3/200316/6/2026
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
ModificadaMedia (6.8)2.1%—Nalin Dahyabhai VTEGnome-terminal3/3/200316/6/2026
VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious…
ModificadaAlta (7.5)43%💥 ExploitMicrosoft Windows 2000 Terminal ServicesMicrosoft Windows 2000Microsoft Windows NTMicrosoft Windows XP7/2/200316/6/2026
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
ModificadaMedia (5)70%💥 ExploitFreebsdLinux KernelMicrosoft Windows 2000Microsoft Windows 2000 Terminal Services+117/1/200316/6/2026
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
ModificadaAlta (7.2)3.2%💥 ExploitApple Terminal31/12/200216/6/2026
Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is executed by Terminal.app window.
ModificadaMedia (5)1.4%—Lucent Ascend MAX RouterLucent Ascend Pipeline RouterLucent Dslterminator31/12/200216/6/2026
Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as hostname, MAC, and IP address of the Ethernet interface via a discard (UDP port 9) packet, which causes the device to leak the information…
ModificadaAlta (7.2)1.6%—Microsoft Windows 2000 Terminal Services31/12/200216/6/2026
The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
ModificadaAlta (7.5)16%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.
ModificadaAlta (10)15%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.
ModificadaMedia (5)14%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."
Orbitaley — Vulnerabilidades