Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

388 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.1%💥 ExploitFestalon9/8/200616/6/2026
The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative LoadAddr value in a HES file, which is used as an offset in a memcpy operation and leads to a buffer underflow.
ModificadaMedia (6.8)3.5%—Vastal I-tech Buddy Zone10/7/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Buddy Zone 1.0.1 allow remote attackers to inject arbitrary HTML and web script via the (1) cat_id parameter to (a) view_classifieds.php; (2) id parameter in (b) view_ad.php; (3) event_id parameter in (c) view_event.php, (d) delete_event.php, and (e)…
ModificadaMedia (5)1.6%—Stalker Communigate10/7/200616/6/2026
Unspecified vulnerability in the POP service in Stalker CommuniGate Pro 5.1c1 and earlier allows remote attackers to cause a denial of service (server crash) via unspecified vectors involving opening an empty inbox.
ModificadaBaja (2.1)0.37%—Bitrock Install BuilderProcess-one Ejabberd5/5/200616/6/2026
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this…
ModificadaMedia (4.3)1.8%—Astalavista IT Engineering Contrexx19/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).
ModificadaAlta (7.5)11%💥 ExploitStalker Communigate PRO30/1/200616/6/2026
CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.
ModificadaMedia (5)1.8%—Businessobjects Crystal Enterprise XIBusinessobjects Crystal Reports Server XIBusinessobjects Crystal Reports XIBusinessobjects Report Application Server31/12/200516/6/2026
Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal Reports Server XI, and BusinessObjects Enterprise XI, allows remote attackers to cause a denial of service (application hang) via certain network traffic, possibly…
ModificadaAlta (7.5)1.5%—Coastal Data Management E-quick Cart22/11/200516/6/2026
Multiple SQL injection vulnerabilities in e-Quick Cart allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in shopaddtocart.asp, (2) strpemail parameter in shopprojectlogin.asp, and (3) id parameter in shoptellafriend.asp.
ModificadaMedia (4.3)1.3%—Coastal Data Management E-quick Cart22/11/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in e-Quick Cart allow remote attackers to inject arbitrary web script or HTML via the (1) strgifttoname parameter in shopgift.asp, (2) strfirstname parameter in shopmaillist.asp, (3) strpid parameter in shopprojectlogin.asp, and (4) Custname parameter in…
ModificadaMedia (4.3)1.3%—N-stalker N-stealth8/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response header, which is directly injected into an HTML report.
ModificadaMedia (4.3)1.8%—Astalavista IT Engineering Contrexx3/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.
ModificadaMedia (5)1.8%—Astalavista IT Engineering Contrexx3/8/200516/6/2026
Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.
ModificadaAlta (7.5)1.6%—Astalavista IT Engineering Contrexx3/8/200516/6/2026
Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.
ModificadaMedia (5)2.5%—Stalker Communigate PRO2/5/200516/6/2026
Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages.
ModificadaBaja (1.2)0.30%—Zero G Software InstallanywhereAI31/12/200416/6/2026
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.
ModificadaMedia (4.3)1.2%—Businessobjects Crystal Enterprise31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the URL to a report (RPT) file.
ModificadaAlta (7.5)4.4%💥 ExploitCrystal ART Software Crystal FTP31/12/200416/6/2026
Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that contains a file name with a long extension.
ModificadaAlta (7.5)1.9%—Mcafee Security Installer Control System31/12/200416/6/2026
An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows registry via web pages that use the control's RegQueryValue() method.
ModificadaAlta (10)74%💥 ExploitArush DevastationDreamforge TNN Outdoors PRO HunterEpic Games Unreal EngineEpic Games Unreal Tournament+106/12/200416/6/2026
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b…
ModificadaAlta (10)10%—Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+918/8/200416/6/2026
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the…
ModificadaMedia (6.4)4.1%—Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+918/8/200416/6/2026
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").
ModificadaBaja (2.1)0.43%—Pedestal Software Integrity Protection Driver17/8/200416/6/2026
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.
ModificadaAlta (7.5)72%💥 ExploitBEA Weblogic ServerBorland Software J BuilderBusinessobjects Crystal EnterpriseBusinessobjects Crystal Enterprise Java SDK+56/8/200416/6/2026
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete…
ModificadaMedia (5)1.6%—Businessobjects Crystal EnterpriseBusinessobjects Crystal Reports2/5/200416/6/2026
The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.
ModificadaBaja (2.1)0.33%—Pedestal Software Integrity Protection Driver31/12/200316/6/2026
NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command.
Orbitaley — Vulnerabilidades