Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 11% | 💥 Exploit | Autonomy Ultraseek | 29/1/2009 | 16/6/2026 | Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter. | |
| Modificada | Alta (9.3) | 5.6% | — | Ultravnc | 10/11/2008 | 16/6/2026 | Multiple stack-based buffer overflows in multiple functions in vncviewer/FileTransfer.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | CJ Ultra Plus | 25/9/2008 | 16/6/2026 | SQL injection vulnerability in CJ Ultra Plus 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via an SID cookie. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Ultrashareware Ultra Office Control | 2/9/2008 | 16/6/2026 | Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method. | |
| Modificada | Alta (9.3) | 3.7% | 💥 Exploit | Ultrashareware Ultra Office Control | 2/9/2008 | 16/6/2026 | The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the… | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Ultrastats | 21/7/2008 | 16/6/2026 | SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Jaxultrabb | 2/7/2008 | 16/6/2026 | Directory traversal vulnerability in viewprofile.php in JaxUltraBB 2.0 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the user parameter. party information. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Jaxbot Jaxultrabb | 2/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in viewforum.php in JaxUltraBB (JUBB) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter. | |
| Modificada | Media (4.3) | 9.5% | 💥 Exploit | IDM Computer Solutions INC Ultraedit | 20/6/2008 | 16/6/2026 | Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command. | |
| Modificada | Alta (9.3) | 39% | 💥 Exploit | Ultravnc | 6/2/2008 | 16/6/2026 | Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allows remote attackers to execute arbitrary code or cause a denial of service (crash)… | |
| Modificada | Alta (10) | 17% | — | Ssreader Ultra Star Reader | 8/11/2007 | 16/6/2026 | Stack-based buffer overflow in the pdg2.dll ActiveX control in SSReader 4.0 and earlier allow remote attackers to execute arbitrary code via a long argument to the Register method. NOTE: some details were obtained from third party sources. | |
| Modificada | Media (6.8) | 2.8% | — | Ssreader Ultra Star Reader | 5/11/2007 | 16/6/2026 | Buffer overflow in the register function in Ultra Star Reader ActiveX control in SSReader allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 9.4% | 💥 Exploit | Ultra Shareware Ultra Crypto Component | 17/9/2007 | 16/6/2026 | Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute arbitrary code via (1) a long string in the first argument to the AcquireContext method or (2) an unspecified vector to the DeleteContext method. | |
| Modificada | Media (6.4) | 5.6% | 💥 Exploit | Ultra Shareware Ultra Crypto Component | 17/9/2007 | 16/6/2026 | Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method. | |
| Modificada | Media (4.6) | 0.36% | — | Ultradefrag | 30/7/2007 | 16/6/2026 | Heap-based buffer overflow in the FindFiles function in UltraDefrag 1.0.3 allows local users to gain privileges via a file with a long pathname. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.6) | 55% | 💥 Exploit | EZB Systems Ultraiso | 30/5/2007 | 16/6/2026 | Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information. | |
| Modificada | Media (5) | 1.8% | — | Verity Ultraseek | 18/11/2006 | 16/6/2026 | Verity Ultraseek before 5.7 allows remote attackers to obtain sensitive information via direct requests with (1) a null ("%00") terminated url parameter to help/urlstatusgo.html; or missing parameters to (2) help/header.html, (3) help/footer.html, (4) spell.html, (5) coreforma.html, (6) daterange.html, (7) hits.html,… | |
| Modificada | Alta (10) | 6.5% | — | Verity Ultraseek | 18/11/2006 | 16/6/2026 | Verity Ultraseek before 5.7 allows remote attackers to use the server as a proxy for web attacks and host scanning via a direct request to the highlight/index.html script. | |
| Modificada | Media (5) | 1.7% | — | Verity Ultraseek | 18/11/2006 | 16/6/2026 | Absolute path traversal vulnerability in admin/logfile.txt in Verity Ultraseek before 5.6.2 allows remote attackers to read arbitrary files via the name variable. | |
| Modificada | Alta (7.5) | 1.1% | — | Ultrasite | 16/11/2006 | 16/6/2026 | SQL injection vulnerability in update.asp in UltraSite 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Baja (2.6) | 1.9% | 💥 Exploit | Jaxultrabb | 25/10/2006 | 16/6/2026 | Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script, HTML, or PHP via the contents parameter, whose value is prepended to the file specified by the forum parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Ceary Ultracms | 25/10/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in include/index.php in UltraCMS 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | |
| Modificada | Alta (10) | 2.1% | — | Ultravnc | 5/5/2006 | 16/6/2026 | The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 uses weak encryption (XOR) for challenge/response, which allows remote attackers to gain privileges by sniffing and decrypting passwords. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | EZB Systems Ultraiso | 29/4/2006 | 16/6/2026 | Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image. | |
| Modificada | Alta (9) | 68% | 💥 Exploit | Ultravnc Tabbed ViewerUltravnc VNC Viewer | 6/4/2006 | 16/6/2026 | Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a malicious server that sends a long string to a client that connects on TCP port 5900, which triggers an overflow in Log::ReallyPrint; and (2)… |