Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)2.2%💥 ExploitSage-mozdev Sage11/1/200716/6/2026
Firefox Sage extension 1.3.8 and earlier allows remote attackers to execute arbitrary Javascript in the local context via an RSS feed with an img tag containing the script followed by an extra trailing ">", which Sage modifies to close the img element before the malicious script.
ModificadaMedia (6.6)1.4%—Microsoft Message Compiler5/1/200716/6/2026
Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename. NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed
ModificadaAlta (7.5)1.1%💥 ExploitScriptphp Messageriescripthp14/12/200616/6/2026
SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter.
ModificadaMedia (6.8)2.1%💥 ExploitScriptphp Messageriescripthp14/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the (2) email parameter to (b) existeemail.php, or the (3) pageName or (4) cssform parameter to (c) Contact/contact.php.
ModificadaAlta (7.5)2.5%💥 ExploitMessagerie Locale28/11/200616/6/2026
PHP remote file inclusion vulnerability in centre.php in Messagerie Locale as of 20061127 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)2.2%—Sage12/9/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6 allow remote attackers to inject arbitrary web script or HTML via JavaScript in a content:encoded element within an item element in an RSS feed, as demonstrated by four example content:encoded elements that use XMLHttpRequest to read arbitrary local…
ModificadaMedia (4.3)1.2%—Sage12/9/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Sage allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite.
ModificadaMedia (5.1)9.9%💥 ExploitXMB Software Extreme Message Board17/8/200616/6/2026
Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is…
ModificadaMedia (5.5)0.29%—BusyboxAvaya Aura Application Enablement ServicesAvaya Aura SIP Enablement ServicesAvaya Message Networking+14/4/200616/6/2026
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
ModificadaMedia (4.3)1.2%—Cholod Mysql Based Message Board26/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaAlta (7.5)1.2%💥 ExploitCholod Mysql Based Message Board26/3/200616/6/2026
SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party…
ModificadaMedia (5)1.8%—Compex Netpassage Wpe54g2/3/200616/6/2026
uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778.
ModificadaMedia (4.3)1.2%—Starphire Technologies SitesageStarphire Technologies Sitesage-eeStarphire Technologies Sitesage-leStarphire Technologies Sitesage-sb+122/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Starphire SiteSage 5.0.18 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the norelay_highlight_words parameter.
ModificadaMedia (5)2.4%—Avaya Modular Messaging Message Storage Server22/12/200516/6/2026
POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets.
ModificadaMedia (5)3.1%—Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2023/8/200516/6/2026
Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability."
ModificadaMedia (4.3)1.4%—Simple Message BoardAI19/7/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2) UID parameter to user.cfm, (3) TID parameter to thread.cfm, or (4) PostDate parameter to search.cfm.
ModificadaMedia (5)6.2%—Sophos Anti-virusSophos MailmonitorSophos Mailmonitor FOR Notes DominoSophos Puremessage Anti-virus+119/7/200516/6/2026
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.
ModificadaAlta (7.5)2.1%💥 ExploitMercuryboard Message Board21/6/200516/6/2026
SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
ModificadaMedia (5)1.8%—Colored Scripts Easy Message Board14/5/200516/6/2026
Directory traversal vulnerability in easymsgb.pl in Easy Message Board allows remote attackers to read arbitrary files via a .. (dot dot) in the print parameter.
ModificadaAlta (7.5)3.7%💥 ExploitColored Scripts Easy Message Board14/5/200516/6/2026
easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter.
ModificadaMedia (6.2)2.9%💥 ExploitAvaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+1614/4/200516/6/2026
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
ModificadaBaja (2.1)0.51%—Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+1114/4/200516/6/2026
The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.
ModificadaMedia (4.3)1.2%—Mercuryboard Message Board23/3/200516/6/2026
Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).
ModificadaAlta (7.5)15%💥 ExploitArchive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+199/2/200516/6/2026
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
ModificadaAlta (7.5)15%💥 ExploitArchive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+1927/1/200516/6/2026
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
Orbitaley — Vulnerabilidades