Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

51 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.40%—Dadamailproject Dada Mail20/9/202117/6/2026
Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully crafted web page via email, SMS, etc, that - when visited, allows them control of the list control panel as if the bad actor was logged in themselves. This includes changing any mailing list…
ModificadaMedia (5.5)9.4%—Adamhathcock Sharpcompress25/7/201817/6/2026
SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaAlta (8.1)0.71%—Adamvr-geoip-lite Project Adamvr-geoip-lite29/5/201817/6/2026
adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP, which leaves it vulnerable to MITM attacks. This impacts the integrity and availability of this geoip data that may alter the decisions made by an application using this…
ModificadaAlta (7.5)1.8%—Saadamin Simple Student Result27/9/201717/6/2026
The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.
ModificadaMedia (5.9)0.49%—Northadamsbank Nasb Mobile Bank16/6/201717/6/2026
The North Adams State Bank (Ursa) nasb-mobile-banking/id980573797 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)5.9%💥 ExploitAdvantech Adamview20/1/201517/6/2026
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file.
ModificadaAlta (7.5)2.0%—Adam Zaninovich Sounder29/8/201316/6/2026
lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
ModificadaMedia (5)2.4%—Adam Ross Tokenauth27/6/201216/6/2026
The Token Authentication (tokenauth) module 6.x-1.x before 6.x-1.7 for Drupal does not properly revert user sessions, which might allow remote attackers to perform requests with extra privileges.
ModificadaAlta (10)3.8%—Advantech Adam OPC ServerAdvantech Modbus RTU OPC ServerAdvantech Modbus TCP OPC Server21/2/201216/6/2026
Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM OPC Server before 3.01.012, Modbus RTU OPC Server before 3.01.010, and Modbus TCP OPC Server before 3.01.010 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (5.8)2.0%—Adam Kennedy Crypt-dsa10/10/201116/6/2026
The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a signature, or determine the signing key of a signed message, via a brute-force attack.
ModificadaAlta (9.3)31%💥 ExploitAdammo FAT Player28/7/201016/6/2026
Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.3%—Adam Gerson Moodle Courselist26/10/200916/6/2026
SQL injection vulnerability in Moodle Course List 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.8)39%—Microsoft AdamMicrosoft Windows Server 2003Microsoft Windows 200010/6/200916/6/2026
Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS…
ModificadaAlta (7.5)54%💥 ExploitDadamailproject Dada Mail Manager20/2/200916/6/2026
PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.
ModificadaMedia (6.8)0.87%💥 ExploitAdam Tomecek Ownrs2/2/200916/6/2026
SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (10)3.4%—Advantech Adam-6015Advantech Adam-6017Advantech Adam-6018Advantech Adam-6022+106/1/200916/6/2026
The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP session, and (1) monitor or (2) control the module's Modbus/TCP I/O activity.
ModificadaAlta (7.5)2.3%💥 ExploitAdam Scheinberg Flip25/7/200816/6/2026
PHP remote file inclusion vulnerability in config.php in Adam Scheinberg Flip 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the incpath parameter.
ModificadaAlta (7.5)2.3%💥 ExploitAdam Scheinberg Flip24/9/200716/6/2026
account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register action.
ModificadaMedia (5)6.2%💥 ExploitAdam Scheinberg Flip24/9/200716/6/2026
Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing login credentials via a direct request for var/users.txt.
ModificadaMedia (6.8)5.1%💥 ExploitAdam VAN Dongen COM ForumAdam VAN Dongen Phpbb Component26/6/200716/6/2026
PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
ModificadaAlta (7.5)1.5%—Adam Jarret Ajlogin9/1/200716/6/2026
AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb.
ModificadaAlta (7.5)1.6%—Adam Mmedici File Upload Manager12/6/200516/6/2026
mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.
ModificadaMedia (4.6)1.7%💥 ExploitAdam Webb Nukejokes8/5/200416/6/2026
SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.
ModificadaMedia (5)1.4%—Adam Webb NukejokesAI8/5/200416/6/2026
NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message.
ModificadaMedia (4.3)1.8%💥 ExploitAdam Webb Nukejokes8/5/200416/6/2026
Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.
Orbitaley — Vulnerabilidades