Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Frontrange Iheat | 22/5/2006 | 16/6/2026 | The ActiveX version of FrontRange iHEAT allows remote authenticated users to run arbitrary programs or access arbitrary files on the host machine by uploading a file with an extension that is not associated with an application, and selecting a file from the "Open With..." dialog. | |
| Modificada | Media (6.8) | 25% | 💥 Exploit | Microsoft Frontpage Server ExtensionsMicrosoft Sharepoint Team Services | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2)… | |
| Modificada | Media (5) | 4.0% | — | Microsoft Frontpage | 5/7/2005 | 16/6/2026 | Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page. | |
| Modificada | Alta (7.5) | 1.3% | — | Amarok WEB Frontend | 17/6/2005 | 16/6/2026 | amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Esmi Paypal Storefront | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Esmi Paypal Storefront | 2/5/2005 | 16/6/2026 | Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory. | |
| Modificada | Alta (9) | 1.7% | — | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter. | |
| Modificada | Media (5) | 12% | — | Microsoft FrontpageMicrosoft IE | 31/12/2004 | 16/6/2026 | asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values. | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation. | |
| Modificada | Alta (7.5) | 42% | — | Microsoft FrontpageMicrosoft OfficeMicrosoft PublisherMicrosoft Word+1 | 28/9/2004 | 16/6/2026 | Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website. | |
| Modificada | Media (5) | 1.7% | — | Infrontech Webtide | 31/12/2003 | 16/6/2026 | WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?"). | |
| Modificada | Alta (7.5) | 83% | 💥 Exploit | Microsoft Frontpage Server ExtensionsMicrosoft Sharepoint Team ServicesMicrosoft Windows 2000Microsoft Windows XP | 15/12/2003 | 16/6/2026 | Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request. | |
| Modificada | Media (5) | 37% | — | Microsoft Frontpage Server ExtensionsMicrosoft Sharepoint Team ServicesMicrosoft Windows 2000Microsoft Windows XP | 15/12/2003 | 16/6/2026 | Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Lagarde Storefront | 18/8/2003 | 16/6/2026 | SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field. | |
| Modificada | Alta (7.5) | 2.9% | — | Frontrange Goldmine | 9/6/2003 | 16/6/2026 | FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Outfront Spooky Login | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field. | |
| Modificada | Alta (7.5) | 18% | — | Microsoft Frontpage Server ExtensionsMicrosoft Windows 2000Microsoft Windows XP | 10/10/2002 | 16/6/2026 | Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request. | |
| Modificada | Alta (10) | 2.1% | — | Christof Pohl Improved MOD Frontpage | 12/8/2002 | 16/6/2026 | Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges. | |
| Modificada | Alta (7.5) | 28% | 💥 Exploit | Microsoft Frontpage Server ExtensionsMicrosoft Windows 2000Microsoft Windows NT | 21/7/2001 | 16/6/2026 | Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll. | |
| Modificada | Media (5) | 20% | 💥 Exploit | Microsoft FrontpageMicrosoft Personal WEB Server | 12/3/2001 | 16/6/2026 | Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL. | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Mirabilis ICQ WEB Front | 11/12/2000 | 23/9/2026 | ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character. |