Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 4.4% | 💥 Exploit | Wavelink Media Tutorialcms | 22/5/2007 | 16/6/2026 | TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Wavelink Media Tutorialcms | 11/5/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e)… | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | Wavelink Media Tutorialcms | 11/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e)… | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Alessandro Lulli Wavewoo | 25/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_include parameter. | |
| Modificada | Alta (7.5) | 29% | 💥 Exploit | Macromedia Shockwave | 10/3/2007 | 16/6/2026 | Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress… | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Media (4.3) | 7.9% | 💥 Exploit | Macromedia Shockwave | 31/12/2006 | 16/6/2026 | An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute. | |
| Modificada | Alta (9.3) | 20% | — | Adobe Shockwave Player | 31/12/2005 | 16/6/2026 | Stack-based buffer overflow in an ActiveX control for the installer for Adobe Macromedia Shockwave Player 10.1.0.11 and earlier allows remote attackers to execute arbitrary code via crafted large values for unspecified parameters. | |
| Modificada | Alta (7.5) | 1.6% | — | Arcowave Systems Wlan AP + Adsl Router | 14/5/2005 | 16/6/2026 | Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell. | |
| Modificada | Media (5) | 3.7% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security+6 | 31/12/2004 | 16/6/2026 | Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface. | |
| Modificada | Media (5) | 3.2% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security 320+8 | 31/12/2004 | 16/6/2026 | Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file. | |
| Modificada | Media (5) | 3.9% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security 320+8 | 31/12/2004 | 16/6/2026 | Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a… | |
| Modificada | Media (5) | 1.9% | — | Macromedia Flash PlayerMacromedia Shockwave | 22/4/2003 | 16/6/2026 | Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file). | |
| Modificada | Alta (7.5) | 3.2% | — | Macromedia Shockwave Flash | 12/8/2002 | 16/6/2026 | The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than the specified length. | |
| Modificada | Media (6.4) | 0.68% | — | CMG Openwave WAP Gateway | 31/12/2001 | 16/6/2026 | Openwave WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack. | |
| Modificada | Crítica (9.8) | 1.9% | — | Lightwavemo Consoleserver 3200 Firmware | 2/7/2001 | 16/6/2026 | Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing. | |
| Modificada | Media (5) | 2.1% | — | Lightwave Consoleserver | 2/7/2001 | 16/6/2026 | The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users. | |
| Modificada | Alta (7.6) | 1.7% | — | Macromedia Shockwave Flash Plugin | 26/3/2001 | 16/6/2026 | Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Unify Ewave Servletexec | 9/1/2001 | 16/6/2026 | Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20". | |
| Modificada | Media (5) | 0.80% | — | Lucent WavelanOrinoco Wavelan | 1/1/2001 | 16/6/2026 | Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages. | |
| Modificada | Media (5) | 8.5% | 💥 Exploit | Unify Ewave Servletexec | 11/12/2000 | 16/6/2026 | eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running. | |
| Modificada | Alta (10) | 5.1% | — | Unify Ewave Servletexec | 11/12/2000 | 23/9/2026 | eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands. | |
| Modificada | Alta (7.5) | 2.3% | — | Unify Ewave Servletexec | 8/6/2000 | 16/6/2026 | Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. | |
| Modificada | Media (5) | 1.1% | — | Macromedia Shockwave Flash Plugin | 11/3/1999 | 16/6/2026 | Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia. | |
| Modificada | Media (5.1) | 1.2% | — | Macromedia Shockwave Flash Plugin | 14/3/1997 | 16/6/2026 | Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie. |