Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 31% | 💥 Exploit | Photodex Proshow Gold | 16/9/2009 | 16/6/2026 | Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code via a crafted Slideshow project (.psh) file, related to the (1) cell[n].images[m].image and (2) cell[n].sound.file fields. | |
| Modificada | Alta (9.3) | 5.5% | 💥 Exploit | Heroshare Hero Super Player 3000 | 4/9/2009 | 16/6/2026 | Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504. | |
| Modificada | Media (4.3) | 1.1% | — | Yoshinori Tahara MycaljpGeeklog | 31/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Site Calendar 'mycaljp' plugin 2.0.0 through 2.0.6, as used in the Japanese extended package of Geeklog 1.5.0 through 1.5.2 and when distributed 20090629 or earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Joshua Oliver Really Simple CMS | 17/8/2009 | 16/6/2026 | Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter. | |
| Modificada | Alta (7.2) | 0.36% | — | Forkosh Mathtex | 14/7/2009 | 16/6/2026 | mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors. | |
| Modificada | Alta (10) | 2.7% | — | Forkosh Mathtex | 14/7/2009 | 16/6/2026 | Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded before 20090713, have unspecified impact and remote attack vectors. | |
| Modificada | Alta (10) | 2.3% | — | Forkosh Mimetex | 14/7/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives. | |
| Modificada | Alta (7.5) | 2.2% | — | Forkosh Mathtex | 14/7/2009 | 16/6/2026 | The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute arbitrary commands via shell metacharacters in the dpi tag. | |
| Modificada | Alta (10) | 9.0% | — | Forkosh Mimetex | 14/7/2009 | 16/6/2026 | Multiple stack-based buffer overflows in mimetex.cgi in mimeTeX, when downloaded before 20090713, allow remote attackers to execute arbitrary code via a TeX file with long (1) picture, (2) circle, or (3) input tags. | |
| Modificada | Media (6.9) | 0.36% | — | Toshiba Face Recognition | 20/2/2009 | 16/6/2026 | Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large number of images for which the viewpoint and lighting have been modified to match a stored image of the authorized notebook user. | |
| Modificada | Alta (10) | 90% | 💥 Exploit | Zeroshell | 12/2/2009 | 16/6/2026 | cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action. | |
| Modificada | Media (6.5) | 4.5% | 💥 Exploit | Ryneezy Phosheezy | 26/1/2009 | 16/6/2026 | Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information… | |
| Modificada | Media (6.5) | 5.6% | 💥 Exploit | Ryneezy Phosheezy | 22/1/2009 | 16/6/2026 | Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained… | |
| Modificada | Media (5) | 6.3% | 💥 Exploit | Ryneezy Phosheezy | 22/1/2009 | 16/6/2026 | Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator's password hash via a direct request for config/password. | |
| Modificada | Media (6.9) | 0.31% | — | Fumitoshi Ukai FML | 5/11/2008 | 16/6/2026 | mead.pl in fml 4.0.3 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/debugbuf temporary file. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Pars4u Videosharing | 22/8/2008 | 16/6/2026 | SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Pars4u Videosharing | 22/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in members.php in Pars4u Videosharing 1 allows remote attackers to inject arbitrary web script or HTML via the PageNo parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Caupo.net Cauposhop Classic | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to execute arbitrary SQL commands via the saArticle[ID] parameter. | |
| Modificada | Alta (7.1) | 0.77% | — | Akamai Technologies ClientRED Swoosh Client | 9/6/2008 | 16/6/2026 | The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery… | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Thomas Voecking Internet Photoshow | 18/5/2008 | 16/6/2026 | admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true. | |
| Modificada | Alta (9.3) | 20% | 💥 Exploit | Adobe Photoshop | 23/4/2008 | 16/6/2026 | Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Highwood Design Hwdvideoshare | 22/2/2008 | 16/6/2026 | SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php. | |
| Modificada | Media (6.8) | 8.0% | 💥 Exploit | Toshiba Surveillix | 23/1/2008 | 16/6/2026 | Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Caupo.net Cauposhop PRO | 1/11/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary PHP code via a URL in the action parameter. | |
| Modificada | Alta (9.3) | 41% | 💥 Exploit | Adobe GoliveAdobe IllustratorAdobe PhotoshopAdobe Photoshop Elements | 30/4/2007 | 16/6/2026 | Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file. |