Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

472 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)4.5%💥 ExploitBarracuda Networks Barracuda Spam Firewall23/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
ModificadaAlta (7.5)2.3%💥 ExploitGuillaume Meister PHP Spammanager2/4/200816/6/2026
Directory traversal vulnerability in body.php in phpSpamManager (phpSM) 0.53 beta allows remote attackers to read arbitrary local files via a .. (dot dot) in the filename parameter.
ModificadaMedia (4.3)1.9%—Wordpress Math Comment Spam Protection Plugin10/1/200816/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to…
ModificadaMedia (4.3)1.9%—Wordpress Math Comment Spam Protection Plugin10/1/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to…
ModificadaMedia (4.3)1.5%—Peters Software Random Anti-spam Image10/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form.
ModificadaAlta (9.3)3.9%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+95/10/200716/6/2026
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
ModificadaAlta (9.3)6.0%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+95/10/200716/6/2026
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
ModificadaMedia (4.3)1.6%—Barracuda Networks Barracuda Spam Firewall24/9/200716/6/2026
Cross-site scripting (XSS) vulnerability in the Web administration interface in Barracuda Spam Firewall before firmware 3.5.10.016 allows remote attackers to inject arbitrary web script or HTML via the username field in a login attempt, which is not properly handled when the Monitor Web Syslog screen is open.
ModificadaAlta (7.5)1.4%—Anti-spam Smtp Proxy Server10/8/200716/6/2026
Unspecified vulnerability in assp.pl in Anti-Spam SMTP Proxy Server (ASSP) 1.3.3 has unknown impact and attack vectors.
ModificadaMedia (4.4)0.28%—Kaspersky LAB Kaspersky Anti-spam8/8/200716/6/2026
Kaspersky Anti-Spam 3.0 MP1 before Critical Fix 2 (3.0.278.4) sets incorrect permissions for application files in certain upgrade scenarios, which might allow local users to gain privileges.
ModificadaMedia (6.9)1.1%💥 ExploitSymantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+215/7/200716/6/2026
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt…
ModificadaAlta (7.5)1.7%—Kaspersky LAB Kaspersky Anti-spam30/6/200716/6/2026
Unspecified vulnerability in the web-based product configuration system in Kaspersky Anti-Spam before 3.0 MP1 allows remote attackers to obtain access to certain directories.
ModificadaBaja (1.9)0.34%—Spamassassin11/6/200716/6/2026
SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.
ModificadaAlta (7.8)3.2%—AmavisAvast AntivirusAvast Antivirus HomeAvast Antivirus Professional+99/5/200716/6/2026
unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
ModificadaMedia (4.9)1.7%💥 ExploitSymantec AntivirusSymantec Client SecuritySymantec Norton 360Symantec Norton Antispam+42/4/200716/6/2026
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2)…
ModificadaBaja (1.9)0.86%💥 ExploitSymantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+216/3/200716/6/2026
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's…
ModificadaMedia (4.3)6.9%—Apache Spamassassin16/2/200716/6/2026
Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
ModificadaMedia (6.4)0.88%—PAM SSH8/2/200716/6/2026
The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.
ModificadaAlta (7.2)0.40%—Andrew Morgan Linux PAM23/1/200716/6/2026
pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.
ModificadaBaja (2.1)0.31%—PAM Extern3/11/200616/6/2026
PAM_extern before 0.2 sends a password as a command line argument, which allows local users to obtain the password by listing the command line arguments, such as ps. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)3.3%💥 ExploitSpamoborona18/10/200616/6/2026
PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
ModificadaMedia (6.8)5.5%💥 ExploitPhpbb Spamblockermod17/10/200616/6/2026
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
ModificadaMedia (4)1.1%—John Hanna Anti-spam Smtp Proxy Server21/8/200616/6/2026
Absolute path traversal vulnerability in the get functionality in Anti-Spam SMTP Proxy (ASSP) allows remote authenticated users to read arbitrary files via (1) C:\ (Windows drive letter), (2) UNC, and possibly other types of paths in the file parameter.
ModificadaMedia (5.1)3.1%💥 ExploitSpaminator16/8/200616/6/2026
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
ModificadaAlta (7.2)0.36%—Barracuda Networks Barracuda Spam Firewall11/8/200616/6/2026
Barracuda Spam Firewall (BSF), possibly 3.3.03.053, contains a hardcoded password for the admin account for logins from 127.0.0.1 (localhost), which allows local users to gain privileges.