Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)32%💥 ExploitAdobe GoliveAdobe IllustratorAdobe Photoshop25/4/200716/6/2026
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.
ModificadaAlta (7.5)1.4%—Onelook Oboshop11/4/200716/6/2026
Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
ModificadaAlta (9.3)36%💥 ExploitAltdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+7724/1/200716/6/2026
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and…
ModificadaAlta (10)2.3%—Toshiba Bluetooth31/12/200616/6/2026
Unspecified vulnerability in the Toshiba Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.
ModificadaAlta (7.5)3.3%💥 ExploitYuuki Yoshizawa Exporia15/11/200616/6/2026
PHP remote file inclusion vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: SecurityFocus disputes this issue, saying "further analysis reveals that the application is not vulnerable." NOTE: this issue may overlap…
ModificadaAlta (10)1.4%—Toshiba Bluetooth Stack31/10/200616/6/2026
Unspecified vulnerability in Toshiba Bluetooth Stack before 4.20.01 has unspecified impact and attack vectors, related to the 4.20.01(T) "Security fix." NOTE: due to the lack of details in the vendor advisory, it is not clear whether this issue is related to CVE-2006-5405.
ModificadaMedia (6.2)0.38%—Toshiba Bluetooth Wireless Device Driver19/10/200616/6/2026
Unspecified vulnerability in Toshiba Bluetooth wireless device driver 3.x and 4 through 4.00.35, as used in multiple products, allows physically proximate attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via crafted Bluetooth packets.
ModificadaAlta (7.5)2.9%💥 ExploitJoshua Muheim Phpmywebmin10/10/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the target parameter in (1) change_preferences2.php, (2) create_file.php, (3) upload_local.php, and (4) upload_multi.php, different vectors than CVE-2006-5124.
ModificadaAlta (7.5)3.5%💥 ExploitJoshua Muheim Phpmywebmin3/10/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) target and (2) action parameters in window.php, and possibly the (3) target parameter in home.php.
ModificadaAlta (7.5)1.6%—Yuuki Yoshizawa Exporia3/10/200616/6/2026
Directory traversal vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to include and execute local files via a .. (dot dot) in the lan parameter to includes.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)3.7%💥 ExploitJoshua Muheim Phpmywebmin3/10/200616/6/2026
Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which triggers a directory listing through the opendir function.
ModificadaMedia (5)2.5%—Toshiba Bluetooth Stack22/6/200616/6/2026
The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a denial of service (reboot) via a L2CAP echo request that triggers an out-of-bounds memory access, similar to "Ping o' Death" and as demonstrated by BlueSmack. NOTE: this issue was originally reported…
ModificadaAlta (7.5)1.3%💥 ExploitCosmoshop19/5/200616/6/2026
SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter.
ModificadaAlta (7.8)1.7%—Cosmoshop19/5/200616/6/2026
Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.
ModificadaAlta (7.5)3.9%💥 ExploitThomas Voecking Internet Photoshow20/4/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
ModificadaMedia (4.6)1.3%—Adobe AcrobatAdobe Acrobat ReaderAdobe Creative SuiteAdobe Illustrator+52/2/200616/6/2026
Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.
ModificadaMedia (5)2.5%—Toshiba Bluetooth Stack14/1/200616/6/2026
Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.
ModificadaAlta (7.5)14%💥 ExploitJoshua Eichorn Phpdocumentor31/12/200516/6/2026
PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2) the root_dir parameter in docbuilder/file_dialog.php.
ModificadaAlta (7.2)1.1%💥 ExploitOSH11/12/200516/6/2026
Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.
ModificadaAlta (7.2)0.85%💥 ExploitOSH20/11/200516/6/2026
Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.
ModificadaMedia (6.8)2.2%💥 ExploitAenovoAenovoshopAenovowysi14/10/200516/6/2026
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages.
ModificadaMedia (4.6)0.48%—AenovoAenovoshopAenovowysi14/10/200516/6/2026
Aenovo products (1) aeNovo, (2) aeNovoShop, and (3) aeNovoWYSI store password information in plaintext in the (a) control, (b) content, and (c) page tables, which allows attackers with database access to obtain those passwords and gain privileges.
ModificadaMedia (5)14%💥 ExploitMicrosoft IE FOR Macintosh27/9/200516/6/2026
Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in a BGSOUND tag, possibly involving double-quotes in an about: URI.
ModificadaAlta (7.5)1.3%—Cosmoshop2/9/200516/6/2026
SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors.
ModificadaMedia (5)1.2%—Cosmoshop2/9/200516/6/2026
Directory traversal vulnerability in bestmail_edit.cgi in cosmoshop 8.10.78 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.