Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.40% | — | Dadamailproject Dada Mail | 20/9/2021 | 17/6/2026 | Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully crafted web page via email, SMS, etc, that - when visited, allows them control of the list control panel as if the bad actor was logged in themselves. This includes changing any mailing list… | |
| Modificada | Media (5.5) | 9.4% | — | Adamhathcock Sharpcompress | 25/7/2018 | 17/6/2026 | SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Alta (8.1) | 0.71% | — | Adamvr-geoip-lite Project Adamvr-geoip-lite | 29/5/2018 | 17/6/2026 | adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP, which leaves it vulnerable to MITM attacks. This impacts the integrity and availability of this geoip data that may alter the decisions made by an application using this… | |
| Modificada | Alta (7.5) | 1.8% | — | Saadamin Simple Student Result | 27/9/2017 | 17/6/2026 | The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number. | |
| Modificada | Media (5.9) | 0.49% | — | Northadamsbank Nasb Mobile Bank | 16/6/2017 | 17/6/2026 | The North Adams State Bank (Ursa) nasb-mobile-banking/id980573797 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 5.9% | 💥 Exploit | Advantech Adamview | 20/1/2015 | 17/6/2026 | Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file. | |
| Modificada | Alta (7.5) | 2.0% | — | Adam Zaninovich Sounder | 29/8/2013 | 16/6/2026 | lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a filename. | |
| Modificada | Media (5) | 2.4% | — | Adam Ross Tokenauth | 27/6/2012 | 16/6/2026 | The Token Authentication (tokenauth) module 6.x-1.x before 6.x-1.7 for Drupal does not properly revert user sessions, which might allow remote attackers to perform requests with extra privileges. | |
| Modificada | Alta (10) | 3.8% | — | Advantech Adam OPC ServerAdvantech Modbus RTU OPC ServerAdvantech Modbus TCP OPC Server | 21/2/2012 | 16/6/2026 | Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM OPC Server before 3.01.012, Modbus RTU OPC Server before 3.01.010, and Modbus TCP OPC Server before 3.01.010 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.8) | 2.0% | — | Adam Kennedy Crypt-dsa | 10/10/2011 | 16/6/2026 | The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a signature, or determine the signing key of a signed message, via a brute-force attack. | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | Adammo FAT Player | 28/7/2010 | 16/6/2026 | Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.3% | — | Adam Gerson Moodle Courselist | 26/10/2009 | 16/6/2026 | SQL injection vulnerability in Moodle Course List 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.8) | 39% | — | Microsoft AdamMicrosoft Windows Server 2003Microsoft Windows 2000 | 10/6/2009 | 16/6/2026 | Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS… | |
| Modificada | Alta (7.5) | 54% | 💥 Exploit | Dadamailproject Dada Mail Manager | 20/2/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter. | |
| Modificada | Media (6.8) | 0.87% | 💥 Exploit | Adam Tomecek Ownrs | 2/2/2009 | 16/6/2026 | SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 3.4% | — | Advantech Adam-6015Advantech Adam-6017Advantech Adam-6018Advantech Adam-6022+10 | 6/1/2009 | 16/6/2026 | The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP session, and (1) monitor or (2) control the module's Modbus/TCP I/O activity. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Adam Scheinberg Flip | 25/7/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in Adam Scheinberg Flip 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the incpath parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Adam Scheinberg Flip | 24/9/2007 | 16/6/2026 | account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register action. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Adam Scheinberg Flip | 24/9/2007 | 16/6/2026 | Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing login credentials via a direct request for var/users.txt. | |
| Modificada | Media (6.8) | 5.1% | 💥 Exploit | Adam VAN Dongen COM ForumAdam VAN Dongen Phpbb Component | 26/6/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Adam Jarret Ajlogin | 9/1/2007 | 16/6/2026 | AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb. | |
| Modificada | Alta (7.5) | 1.6% | — | Adam Mmedici File Upload Manager | 12/6/2005 | 16/6/2026 | mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action. | |
| Modificada | Media (4.6) | 1.7% | 💥 Exploit | Adam Webb Nukejokes | 8/5/2004 | 16/6/2026 | SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter. | |
| Modificada | Media (5) | 1.4% | — | Adam Webb NukejokesAI | 8/5/2004 | 16/6/2026 | NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Adam Webb Nukejokes | 8/5/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function. |