Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

454 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.94%—Nathan Haug Filefield Sources3/12/201216/6/2026
Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
ModificadaMedia (6.8)0.93%—Larry Garfield Autosave14/8/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the Autosave module 6.x before 6.x-2.10 and 7.x-2.x before 7.x-2.0 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests involving "submitting saved results to a node."
ModificadaMedia (6.8)3.7%💥 ExploitEA Battlefield 2EA Battlefield 21422/7/201016/6/2026
Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via "..\" (dot dot backslash) sequences in URLs for the (1) sponsor or (2)…
ModificadaBaja (2.1)0.99%—Quicksketch Filefield21/6/201016/6/2026
Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).
ModificadaAlta (7.5)13%💥 ExploitCOM Perchafieldsattach25/5/201016/6/2026
Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaBaja (2.1)1.0%—Kevinhankens Tablefield20/5/201016/6/2026
Cross-site scripting (XSS) vulnerability in the CCK TableField module 6.x before 6.x-1.2 for Drupal allows remote authenticated users, with certain node creation or editing privileges, to inject arbitrary web script or HTML via table headers.
ModificadaAlta (7.5)2.2%—Quicksketch Filefield26/10/200916/6/2026
The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.
ModificadaMedia (6.5)0.86%💥 ExploitFormfields Adman16/2/200916/6/2026
SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbitrary SQL commands via the campaignId parameter.
ModificadaMedia (6.8)0.98%💥 ExploitMyiosoft Easyclassifields15/9/200816/6/2026
SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse action.
ModificadaBaja (3.5)0.84%—Drupal Asin Field ModuleDrupalDrupal E-commerce ModuleDrupal Fullname Field FOR CCK+622/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments…
ModificadaAlta (7.5)1.7%—Drupal Audio ModuleDrupal Getid3Drupal Mediafield Module21/2/200716/6/2026
Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arbitrary directories, and write to empty files or .mp3 files via unknown vectors.
ModificadaMedia (5)5.7%—Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server21/7/200616/6/2026
Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php…
ModificadaMedia (4)2.1%—Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server21/7/200616/6/2026
Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer before 8.5.0.5 allows remote authenticated users to include arbitrary files via a modified language parameter and a full Windows or UNC pathname in the…
ModificadaMedia (6.5)8.5%💥 ExploitDeerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server28/12/200516/6/2026
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL…
ModificadaAlta (7.5)11%💥 ExploitDeerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server28/12/200516/6/2026
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters…
ModificadaMedia (5)8.6%💥 ExploitDeerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server28/12/200516/6/2026
mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows remote attackers to access arbitrary files…
ModificadaMedia (5)9.5%💥 ExploitDeerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server28/12/200516/6/2026
dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directory traversal vulnerability.
ModificadaMedia (5)3.3%💥 ExploitDigital Illusions Battlefield 1942Digital Illusions Battlefield Vietnam10/1/200516/6/2026
Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference.
ModificadaAlta (7.5)4.5%💥 ExploitElectronic Arts Battlefield 194231/12/200316/6/2026
Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.
ModificadaMedia (5)2.8%—Deerfield Visnetic Website18/8/200316/6/2026
VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe.
ModificadaMedia (4.3)1.5%💥 ExploitDeerfield Visnetic Website31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.
ModificadaMedia (5)4.9%—Deerfield D2gfxWorking Resources Inc. Badblue31/12/200216/6/2026
Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents.
ModificadaMedia (5)1.2%—Deerfield Website PRO31/12/200216/6/2026
WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name.
ModificadaMedia (5)1.6%—Deerfield Visnetic Website31/12/200216/6/2026
Buffer overflow in httpd32.exe in Deerfield VisNetic WebSite before 3.5.15 allows remote attackers to cause a denial of service (crash) via a long HTTP OPTIONS request.
ModificadaMedia (5)2.6%—Deerfield FTP Serv-u14/11/200016/6/2026
FTP Serv-U 2.5e allows remote attackers to cause a denial of service by sending a large number of null bytes.