Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

426 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.4%💥 ExploitB2evolution10/12/200616/6/2026
PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.
ModificadaMedia (6.8)1.9%💥 ExploitB2evolution1/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl…
ModificadaMedia (6.8)1.9%💥 ExploitPhoenix Evolution CMS29/9/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the…
ModificadaAlta (7.5)2.5%💥 ExploitComscripts News Evolution11/9/200616/6/2026
PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter in (1) install.php and (2) migrateNE2toNE3.php.
ModificadaAlta (7.5)1.3%💥 ExploitFull Revolution Aspweblinks6/6/200616/6/2026
SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter.
ModificadaMedia (5)1.8%💥 ExploitFull Revolution Aspweblinks6/6/200616/6/2026
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.
ModificadaBaja (2.6)2.1%—Gnome Evolution2/6/200616/6/2026
Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null pointer is used.
ModificadaMedia (5)2.0%—Gnome Evolution10/3/200616/6/2026
GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.
ModificadaMedia (5)11%💥 ExploitGnome Evolution2/2/200616/6/2026
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to…
ModificadaAlta (7.5)4.4%—Gnome Evolution12/8/200516/6/2026
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.
ModificadaAlta (7.5)4.4%—Gnome Evolution12/8/200516/6/2026
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.
ModificadaMedia (5)1.7%—Ximian Evolution2/5/200516/6/2026
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
ModificadaMedia (5)1.7%—Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+52/5/200516/6/2026
Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that…
ModificadaMedia (5)3.1%💥 ExploitFunlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+52/5/200516/6/2026
Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has…
ModificadaCrítica (9.8)3.2%—Gnome EvolutionDebian Linux24/1/200516/6/2026
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.
ModificadaAlta (7.5)2.4%💥 ExploitFullrevolution Aspwebalbum31/12/200416/6/2026
SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a…
ModificadaAlta (7.5)4.1%💥 ExploitFull Revolution Aspwebcalendar31/12/200416/6/2026
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.
ModificadaMedia (5)3.4%💥 ExploitEvolutionx23/11/200416/6/2026
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.
ModificadaAlta (7.5)2.2%—Ximian Evolution16/6/200316/6/2026
The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.
ModificadaMedia (5)3.4%—Microsoft Outlook ExpressMozillaMuttQualcomm Eudora+416/6/200316/6/2026
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
ModificadaMedia (5)0.92%—Ximian Evolution22/4/200316/6/2026
The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack.
ModificadaMedia (5)10%💥 ExploitXimian Evolution24/3/200316/6/2026
The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.
ModificadaMedia (5)17%💥 ExploitXimian Evolution24/3/200316/6/2026
The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.
ModificadaMedia (5)12%💥 ExploitXimian Evolution24/3/200316/6/2026
Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.
ModificadaMedia (5)1.6%—Ximian Evolution31/12/200216/6/2026
Evolution 1.0.3 and 1.0.4 allows remote attackers to cause a denial of service (memory consumption and crash) via an email with a malformed MIME header.