Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.53% | — | Compaq Presario A900Compaq Presario C700HP G7000Hpqflash FOR HP Notebook System Bios | 31/3/2008 | 16/6/2026 | Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged access via unspecified vectors, possibly involving an authentication bypass of the power-on password. | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | Aurigma Image Uploader Activex ControlFacebookFacebook Photouploader | 8/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Mealex MY Datebook | 6/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter. | |
| Modificada | Baja (2.1) | 0.54% | — | Gabriele Teotino Gnotebook | 1/12/2006 | 16/6/2026 | The Gabriele Teotino GNotebook 0.7.0.1 gadget for Google Desktop stores Gmail passwords in plaintext in the %SYSTEMDRIVE%\temp\Gnotebook.txt log file, which allows local users to obtain passwords by reading the file. | |
| Modificada | Alta (8.3) | 13% | 💥 Exploit | Linksys Wpc300n Wireless-n Notebook Adapter DriverBroadcom Bcmwl5.sys Wireless Device Driver | 14/11/2006 | 16/6/2026 | Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter before 4.100.15.5 and other products, allows remote attackers to execute arbitrary code via an 802.11 response frame containing a long SSID field. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Phprecipebook | 18/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in classes/Import_MM.class.php in PHPRecipeBook 2.36, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the g_rb_basedir parameter. | |
| Modificada | Media (6.8) | 5.8% | 💥 Exploit | Mamboxchange Peoplebook | 17/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals and allow_url_fopen are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Xuebook | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in index.php in xueBook 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Ringtail Casebook | 3/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.asp in Ringtail CaseBook 6.1.0 allows remote attackers to inject arbitrary web script or HTML via the users parameter. | |
| Modificada | Media (5) | 1.4% | — | Ringtail Casebook | 3/11/2005 | 16/6/2026 | login.asp in Ringtail CaseBook 6.1.0 displays different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames. | |
| Modificada | Alta (7.5) | 1.3% | — | Nukebookmarks | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Nukebookmarks | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter. | |
| Modificada | Media (5) | 1.4% | — | Nukebookmarks | 26/3/2005 | 16/6/2026 | marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message. | |
| Modificada | Media (4.3) | 1.2% | — | Phprecipebook | 3/11/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through 2.17 allows remote attackers to inject arbitrary web script or HTML via a recipe. | |
| Modificada | Media (5) | 1.2% | — | THE Magic Notebook | 31/12/2002 | 16/6/2026 | Magic Notebook 1.0b and 1.1b allows remote attackers to cause a denial of service (crash) via an invalid username during login. | |
| Modificada | Alta (7.5) | 7.6% | 💥 Exploit | Scripts FOR Educators Makebook | 4/10/2002 | 16/6/2026 | Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered. | |
| Modificada | Alta (10) | 5.2% | — | FMS Inc. Total VB SourcebookMicrosoft Access | 1/1/1999 | 16/6/2026 | Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. |