Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 5.6% | 💥 Exploit | Sweetphp Totalcalendar | 24/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Itinysoft Studio Total Video Player | 15/2/2007 | 16/6/2026 | Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers to execute arbitrary code via a M3U playlist file that contains a long file name. NOTE: it was later reported that 1.20 and 1.30 are also affected. | |
| Modificada | Media (6.8) | 1.2% | — | Earthlink Total Access | 31/1/2007 | 16/6/2026 | The SpamBlocker.dll ActiveX control in Earthlink TotalAccess is marked "safe for scripting," which allows remote attackers to add arbitrary e-mail addresses and domains to the spam blocker whitelist via the (1) AddSenderToWhitelist and (2) AddDomainToWhitelist functions. | |
| Modificada | Alta (7.1) | 1.6% | — | Total Commander | 16/1/2007 | 16/6/2026 | Unspecified vulnerability in Total Commander before 6.5.6 allows user-assisted remote attackers to delete arbitrary files and corrupt a filesystem via a crafted RAR file. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.3% | — | Total Online Solutions Advanced Webhost Billing System | 1/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in contact.php in Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) AccountUsername and (3) Message parameters. | |
| Modificada | Media (6.4) | 3.1% | 💥 Exploit | Sweetphp Totalcalendar | 20/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Totalecommerce | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE. | |
| Modificada | Media (4.9) | 0.23% | — | Christian Ghisler Total Commander | 7/12/2005 | 16/6/2026 | Total Commander 6.53 uses weak encryption to store FTP usernames and passwords in WCX_FTP.INI, which allows local users to decrypt the passwords and gain access to FTP servers, as possibly demonstrated by the W32.Gudeb worm. | |
| Modificada | Media (4.6) | 0.33% | — | Etnus Totalview | 12/8/2002 | 16/6/2026 | Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users. | |
| Modificada | Media (5) | 2.0% | — | Total PC Solutions PHP Rocket Add-in | 28/12/2001 | 16/6/2026 | Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | |
| Modificada | Alta (10) | 4.1% | 💥 Exploit | Aptis Software Totalbill | 20/10/2000 | 16/6/2026 | The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed. | |
| Modificada | Alta (10) | 5.2% | — | FMS Inc. Total VB SourcebookMicrosoft Access | 1/1/1999 | 16/6/2026 | Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. | |
| Modificada | Alta (7.5) | 1.1% | — | 3com Total Control Netserver Card | 11/5/1998 | 16/6/2026 | US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the "host: " prompt. |