Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9)2.9%—Ultraapps Issue Manager21/12/200516/6/2026
UserProfile.cs in Ultraapps Issue Manager before 2.1 allows remote authenticated users to gain administrator privileges by modifying the original (1) p_User_user_id and (2) User_user_id parameters to UserProfile.aspx, then modifying the password field.
ModificadaAlta (7.5)1.0%💥 ExploitCJ Ultra Plus11/5/200516/6/2026
SQL injection vulnerability in out.php in CJ Ultra (CJUltra) Plus 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via the perm parameter.
ModificadaMedia (4.3)2.4%—Verity Ultraseek22/2/200516/6/2026
Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.
ModificadaMedia (5)1.4%—Verity Ultraseek14/6/200416/6/2026
Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.
ModificadaAlta (7.5)8.5%—ROB Flynn GaimUltramagnetic3/3/200416/6/2026
Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.
ModificadaAlta (7.5)7.6%—ROB Flynn GaimUltramagnetic3/3/200416/6/2026
Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login…
ModificadaAlta (7.5)7.2%—ROB Flynn GaimUltramagnetic3/3/200416/6/2026
Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaMedia (5)1.7%—Ultrafunk Popcorn4/10/200216/6/2026
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Date field that is converted into a year greater than 2037.
ModificadaMedia (5)3.3%💥 ExploitUltrafunk Popcorn4/10/200216/6/2026
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").
ModificadaAlta (7.5)3.9%—Ultrafunk Popcorn4/10/200216/6/2026
Buffer overflow in Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Subject field.
ModificadaMedia (4.6)0.44%💥 ExploitUltraedit-3231/8/200116/6/2026
UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges.
ModificadaBaja (2.1)0.34%—Ultrascripts Ultraboard12/3/200116/6/2026
The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.
ModificadaMedia (5)2.5%💥 ExploitUltrascripts Ultraboard5/5/200016/6/2026
UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself.
ModificadaMedia (5)3.3%💥 ExploitUltrascripts Ultraboard3/5/200016/6/2026
UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.
ModificadaAlta (7.5)7.7%💥 ExploitInfoseek Ultraseek Server15/12/199916/6/2026
Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.
Orbitaley — Vulnerabilidades