Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

489 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.3%—Frontrange Iheat22/5/200616/6/2026
The ActiveX version of FrontRange iHEAT allows remote authenticated users to run arbitrary programs or access arbitrary files on the host machine by uploading a file with an extension that is not associated with an application, and selecting a file from the "Open With..." dialog.
ModificadaMedia (6.8)25%💥 ExploitMicrosoft Frontpage Server ExtensionsMicrosoft Sharepoint Team Services11/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2)…
ModificadaMedia (5)4.0%—Microsoft Frontpage5/7/200516/6/2026
Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.
ModificadaAlta (7.5)1.3%—Amarok WEB Frontend17/6/200516/6/2026
amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.
ModificadaAlta (7.5)1.3%💥 ExploitEsmi Paypal Storefront2/5/200516/6/2026
Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php.
ModificadaMedia (5)2.6%💥 ExploitEsmi Paypal Storefront2/5/200516/6/2026
Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaMedia (5)3.4%💥 ExploitLucasarts Star Wars Battlefront10/1/200516/6/2026
Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.
ModificadaMedia (5)3.1%💥 ExploitLucasarts Star Wars Battlefront10/1/200516/6/2026
Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.
ModificadaAlta (9)1.7%—Aspdotnetstorefront31/12/200416/6/2026
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.
ModificadaMedia (4.3)1.5%💥 ExploitAspdotnetstorefront31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.
ModificadaMedia (4.3)2.2%💥 ExploitAspdotnetstorefront31/12/200416/6/2026
deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.
ModificadaMedia (5)12%—Microsoft FrontpageMicrosoft IE31/12/200416/6/2026
asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.
ModificadaAlta (9.3)49%💥 ExploitMicrosoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+2028/9/200416/6/2026
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
ModificadaAlta (7.5)42%—Microsoft FrontpageMicrosoft OfficeMicrosoft PublisherMicrosoft Word+128/9/200416/6/2026
Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
ModificadaMedia (5)1.7%—Infrontech Webtide31/12/200316/6/2026
WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?").
ModificadaAlta (7.5)83%💥 ExploitMicrosoft Frontpage Server ExtensionsMicrosoft Sharepoint Team ServicesMicrosoft Windows 2000Microsoft Windows XP15/12/200316/6/2026
Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.
ModificadaMedia (5)37%—Microsoft Frontpage Server ExtensionsMicrosoft Sharepoint Team ServicesMicrosoft Windows 2000Microsoft Windows XP15/12/200316/6/2026
Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.
ModificadaAlta (7.5)1.0%💥 ExploitLagarde Storefront18/8/200316/6/2026
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.
ModificadaAlta (7.5)2.9%—Frontrange Goldmine9/6/200316/6/2026
FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.
ModificadaAlta (7.5)2.7%💥 ExploitOutfront Spooky Login31/12/200216/6/2026
SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field.
ModificadaAlta (7.5)18%—Microsoft Frontpage Server ExtensionsMicrosoft Windows 2000Microsoft Windows XP10/10/200216/6/2026
Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
ModificadaAlta (10)2.1%—Christof Pohl Improved MOD Frontpage12/8/200216/6/2026
Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges.
ModificadaAlta (7.5)28%💥 ExploitMicrosoft Frontpage Server ExtensionsMicrosoft Windows 2000Microsoft Windows NT21/7/200116/6/2026
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.
ModificadaMedia (5)20%💥 ExploitMicrosoft FrontpageMicrosoft Personal WEB Server12/3/200116/6/2026
Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.
ModificadaMedia (5)5.2%💥 ExploitMirabilis ICQ WEB Front11/12/200023/9/2026
ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.