Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Typo3 DAM Frontend Extension | 7/7/2008 | 16/6/2026 | Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors related to "broken access control." | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 SQL Frontend Extension | 7/7/2008 | 16/6/2026 | SQL injection vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Typo3 SQL Frontend Extension | 7/7/2008 | 16/6/2026 | Unspecified vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Media (5) | 1.2% | — | Typo3 DAM Frontend Extension | 7/7/2008 | 16/6/2026 | Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 DAM Frontend Extension | 7/7/2008 | 16/6/2026 | SQL injection vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large… | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438. | |
| Modificada | Alta (7.5) | 1.1% | — | Lagarde Storefront | 17/3/2008 | 16/6/2026 | SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.9% | — | THE Sword Project Diatheke Front ENDTHE Sword Project Sword | 25/2/2008 | 16/6/2026 | diatheke.pl in The SWORD Project Diatheke 1.5.9 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the range parameter. | |
| Modificada | Media (4.3) | 1.0% | — | TOR World COM VoteTOR World I-navigatorTOR World Interactive BBSTOR World Mobile Frontier+6 | 22/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and… | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Battlefront Dropteam | 8/10/2007 | 16/6/2026 | Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information. | |
| Modificada | Alta (7.5) | 4.2% | — | Battlefront Dropteam | 8/10/2007 | 16/6/2026 | Multiple buffer overflows in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via (1) a crafted "0x5c" packet or (2) many 32-bit numbers in a "0x18" packet, or cause a denial of service (crash) via (3) a large "0x4b" packet. | |
| Modificada | Alta (7.5) | 3.5% | — | Battlefront Dropteam | 8/10/2007 | 16/6/2026 | Multiple format string vulnerabilities in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username, (2) password, and (3) nickname fields in a "0x01" packet. | |
| Modificada | Media (6.8) | 1.1% | — | Frontaccounting | 1/10/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.12 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/logout.php or certain PHP scripts under (2) admin/, (3) dimensions/, (4) gl/, (5) inventory/, (6) manufacturing/, (7) purchasing/,… | |
| Modificada | Alta (9.3) | 3.6% | 💥 Exploit | Frontaccounting | 27/9/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/login.php and (2) includes/lang/language.php, different vectors than CVE-2007-4279. | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | Frontaccounting | 9/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter. | |
| Modificada | Media (4.9) | 1.0% | — | Hitachi Cosminexus Application ServerHitachi Cosminexus Collaboration PortalHitachi Cosminexus DeveloperHitachi Cosminexus ERP Integrator+10 | 1/8/2007 | 16/6/2026 | The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's… | |
| Modificada | Media (6.4) | 11% | — | Microsoft FrontpageMicrosoft Office | 7/6/2007 | 16/6/2026 | The CERN Image Map Dispatcher (htimage.exe) in Microsoft FrontPage allows remote attackers to determine the existence, and possibly partial contents, of arbitrary files under the web root via a relative pathname in the PATH_INFO. | |
| Modificada | Media (6.8) | 3.2% | 💥 Exploit | Storefront FOR Gallery Storefront Gallery | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php. | |
| Modificada | Alta (7.1) | 5.4% | 💥 Exploit | Frontbase Relational Database Server | 20/3/2007 | 16/6/2026 | Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name. | |
| Modificada | Alta (9.3) | 30% | — | Microsoft AntigenMicrosoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender+1 | 13/2/2007 | 16/6/2026 | Integer overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, Defender, and Forefront Security, allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file. | |
| Analizada | Alta (8.8) | 43% | ⚠ Explotación activa | Microsoft AccessMicrosoft ExcelMicrosoft Excel ViewerMicrosoft Frontpage+10 | 3/2/2007 | 16/6/2026 | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks. | |
| Modificada | Media (6.8) | 1.2% | — | Outfront Spooky Login | 31/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login/login.asp or (2) login/register.asp. | |
| Modificada | Alta (10) | 1.5% | 💥 Exploit | Outfront Spooky Login | 31/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the UserUpdate parameter to login/register.asp or (2) unspecified parameters to includes/a_register.asp. | |
| Modificada | Alta (9.3) | 13% | — | Microsoft AccessMicrosoft ExcelMicrosoft Excel ViewerMicrosoft Frontpage+10 | 10/10/2006 | 16/6/2026 | Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876. |