Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.53%—Compaq Presario A900Compaq Presario C700HP G7000Hpqflash FOR HP Notebook System Bios31/3/200816/6/2026
Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged access via unspecified vectors, possibly involving an authentication bypass of the power-on password.
ModificadaAlta (9.3)38%💥 ExploitAurigma Image Uploader Activex ControlFacebookFacebook Photouploader8/2/200816/6/2026
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.
ModificadaMedia (4.3)1.5%💥 ExploitMealex MY Datebook6/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter.
ModificadaBaja (2.1)0.54%—Gabriele Teotino Gnotebook1/12/200616/6/2026
The Gabriele Teotino GNotebook 0.7.0.1 gadget for Google Desktop stores Gmail passwords in plaintext in the %SYSTEMDRIVE%\temp\Gnotebook.txt log file, which allows local users to obtain passwords by reading the file.
ModificadaAlta (8.3)13%💥 ExploitLinksys Wpc300n Wireless-n Notebook Adapter DriverBroadcom Bcmwl5.sys Wireless Device Driver14/11/200616/6/2026
Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter before 4.100.15.5 and other products, allows remote attackers to execute arbitrary code via an 802.11 response frame containing a long SSID field.
ModificadaAlta (7.5)3.8%💥 ExploitPhprecipebook18/10/200616/6/2026
PHP remote file inclusion vulnerability in classes/Import_MM.class.php in PHPRecipeBook 2.36, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the g_rb_basedir parameter.
ModificadaMedia (6.8)5.8%💥 ExploitMamboxchange Peoplebook17/8/200616/6/2026
PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals and allow_url_fopen are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
ModificadaAlta (7.5)1.1%💥 ExploitXuebook6/6/200616/6/2026
SQL injection vulnerability in index.php in xueBook 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter.
ModificadaMedia (4.3)1.2%—Ringtail Casebook3/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in login.asp in Ringtail CaseBook 6.1.0 allows remote attackers to inject arbitrary web script or HTML via the users parameter.
ModificadaMedia (5)1.4%—Ringtail Casebook3/11/200516/6/2026
login.asp in Ringtail CaseBook 6.1.0 displays different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
ModificadaAlta (7.5)1.3%—Nukebookmarks2/5/200516/6/2026
SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter.
ModificadaMedia (4.3)1.2%—Nukebookmarks2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter.
ModificadaMedia (5)1.4%—Nukebookmarks26/3/200516/6/2026
marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.
ModificadaMedia (4.3)1.2%—Phprecipebook3/11/200316/6/2026
Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through 2.17 allows remote attackers to inject arbitrary web script or HTML via a recipe.
ModificadaMedia (5)1.2%—THE Magic Notebook31/12/200216/6/2026
Magic Notebook 1.0b and 1.1b allows remote attackers to cause a denial of service (crash) via an invalid username during login.
ModificadaAlta (7.5)7.6%💥 ExploitScripts FOR Educators Makebook4/10/200216/6/2026
Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered.
ModificadaAlta (10)5.2%—FMS Inc. Total VB SourcebookMicrosoft Access1/1/199916/6/2026
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.