Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 4.8% | — | Assistanttools MP3 TAG Assistance Professional | 4/12/2009 | 16/6/2026 | Multiple stack-based buffer overflows in Mp3 Tag Assistant Professional 2.92 build 300 allow remote attackers to execute arbitrary code via an MP3 file with a long string in the (1) ID3v1, (2) ID3v2, or (3) APEv2 metadata field. | |
| Modificada | Media (4.3) | 1.2% | — | Puntolatinoclub Gallery Assist Module | 24/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Gallery Assist module 6.x before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via node titles. | |
| Modificada | Alta (9.3) | 5.8% | 💥 Exploit | Assistanttools Music TAG Editor | 27/10/2009 | 16/6/2026 | Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Dotnetindex Professional Download Assistant | 15/12/2008 | 16/6/2026 | Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Dotnetindex Professional Download Assistant | 15/12/2008 | 16/6/2026 | SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 5.4% | 💥 Exploit | Yahoo Assistant | 7/5/2008 | 16/6/2026 | The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption. | |
| Modificada | Alta (9.3) | 4.9% | 💥 Exploit | Softerra Time-assistant | 31/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir parameter. | |
| Modificada | Alta (10) | 10% | — | Supportsoft ScriptrunnerSupportsoft SmartissueSymantec Automated Support AssistantSymantec Norton Antivirus+2 | 22/2/2007 | 16/6/2026 | Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Site-assistant | 9/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Ezhrs HR Assist | 14/12/2006 | 16/6/2026 | SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the Uname (UserName) parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Ezhrs HR Assist | 14/12/2006 | 16/6/2026 | SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Baja (2.6) | 2.6% | — | Symantec Automated Support AssistantSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works | 19/10/2006 | 16/6/2026 | Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.1) | 6.3% | — | Symantec Automated Support AssistantSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works | 19/10/2006 | 16/6/2026 | Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.36% | — | Eduard Bloch Module-assistant | 20/10/2005 | 16/6/2026 | A rule file in module-assistant before 0.9.10 causes a temporary file to be created insecurely, which allows local users to conduct unauthorized operations. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco Personal Assistant | 3/2/2004 | 16/6/2026 | Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username. | |
| Modificada | Media (5) | 2.4% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning. | |
| Modificada | Alta (10) | 3.8% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. | |
| Modificada | Media (6.4) | 1.6% | — | Trolltech QT Assistant | 31/12/2002 | 16/6/2026 | Trolltech Qt Assistant 1.0 in Trolltech Qt 3.0.3, when loaded from the Designer, opens port 7358 for interprocess communication, which allows remote attackers to open arbitrary HTML pages and cause a denial of service. | |
| Modificada | Media (4.6) | 1.9% | — | Oracle Database Assistant | 4/3/1999 | 16/6/2026 | Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file. |