Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)31%💥 ExploitPhotodex Proshow Gold16/9/200916/6/2026
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code via a crafted Slideshow project (.psh) file, related to the (1) cell[n].images[m].image and (2) cell[n].sound.file fields.
ModificadaAlta (9.3)5.5%💥 ExploitHeroshare Hero Super Player 30004/9/200916/6/2026
Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504.
ModificadaMedia (4.3)1.1%—Yoshinori Tahara MycaljpGeeklog31/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in Site Calendar 'mycaljp' plugin 2.0.0 through 2.0.6, as used in the Japanese extended package of Geeklog 1.5.0 through 1.5.2 and when distributed 20090629 or earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.3%💥 ExploitJoshua Oliver Really Simple CMS17/8/200916/6/2026
Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter.
ModificadaAlta (7.2)0.36%—Forkosh Mathtex14/7/200916/6/2026
mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors.
ModificadaAlta (10)2.7%—Forkosh Mathtex14/7/200916/6/2026
Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded before 20090713, have unspecified impact and remote attack vectors.
ModificadaAlta (10)2.3%—Forkosh Mimetex14/7/200916/6/2026
Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives.
ModificadaAlta (7.5)2.2%—Forkosh Mathtex14/7/200916/6/2026
The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute arbitrary commands via shell metacharacters in the dpi tag.
ModificadaAlta (10)9.0%—Forkosh Mimetex14/7/200916/6/2026
Multiple stack-based buffer overflows in mimetex.cgi in mimeTeX, when downloaded before 20090713, allow remote attackers to execute arbitrary code via a TeX file with long (1) picture, (2) circle, or (3) input tags.
ModificadaMedia (6.9)0.36%—Toshiba Face Recognition20/2/200916/6/2026
Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large number of images for which the viewpoint and lighting have been modified to match a stored image of the authorized notebook user.
ModificadaAlta (10)90%💥 ExploitZeroshell12/2/200916/6/2026
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.
ModificadaMedia (6.5)4.5%💥 ExploitRyneezy Phosheezy26/1/200916/6/2026
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information…
ModificadaMedia (6.5)5.6%💥 ExploitRyneezy Phosheezy22/1/200916/6/2026
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained…
ModificadaMedia (5)6.3%💥 ExploitRyneezy Phosheezy22/1/200916/6/2026
Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator's password hash via a direct request for config/password.
ModificadaMedia (6.9)0.31%—Fumitoshi Ukai FML5/11/200816/6/2026
mead.pl in fml 4.0.3 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/debugbuf temporary file.
ModificadaAlta (7.5)0.97%💥 ExploitPars4u Videosharing22/8/200816/6/2026
SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
ModificadaMedia (4.3)1.4%💥 ExploitPars4u Videosharing22/8/200816/6/2026
Cross-site scripting (XSS) vulnerability in members.php in Pars4u Videosharing 1 allows remote attackers to inject arbitrary web script or HTML via the PageNo parameter.
ModificadaAlta (7.5)0.97%💥 ExploitCaupo.net Cauposhop Classic25/6/200816/6/2026
SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to execute arbitrary SQL commands via the saArticle[ID] parameter.
ModificadaAlta (7.1)0.77%—Akamai Technologies ClientRED Swoosh Client9/6/200816/6/2026
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery…
ModificadaAlta (7.5)3.0%💥 ExploitThomas Voecking Internet Photoshow18/5/200816/6/2026
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true.
ModificadaAlta (9.3)20%💥 ExploitAdobe Photoshop23/4/200816/6/2026
Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244.
ModificadaAlta (7.5)0.97%💥 ExploitHighwood Design Hwdvideoshare22/2/200816/6/2026
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.
ModificadaMedia (6.8)8.0%💥 ExploitToshiba Surveillix23/1/200816/6/2026
Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.
ModificadaMedia (6.8)2.1%💥 ExploitCaupo.net Cauposhop PRO1/11/200716/6/2026
PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.
ModificadaAlta (9.3)41%💥 ExploitAdobe GoliveAdobe IllustratorAdobe PhotoshopAdobe Photoshop Elements30/4/200716/6/2026
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.