Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

525 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)4.4%💥 ExploitWavelink Media Tutorialcms22/5/200716/6/2026
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.
ModificadaAlta (7.5)3.7%💥 ExploitWavelink Media Tutorialcms11/5/200716/6/2026
Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e)…
ModificadaMedia (6.8)2.8%💥 ExploitWavelink Media Tutorialcms11/5/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e)…
ModificadaAlta (7.5)3.3%💥 ExploitAlessandro Lulli Wavewoo25/4/200716/6/2026
PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_include parameter.
ModificadaAlta (7.5)29%💥 ExploitMacromedia Shockwave10/3/200716/6/2026
Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress…
ModificadaAlta (9.3)36%💥 ExploitAltdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+7724/1/200716/6/2026
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and…
ModificadaMedia (4.3)7.9%💥 ExploitMacromedia Shockwave31/12/200616/6/2026
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute.
ModificadaAlta (9.3)20%—Adobe Shockwave Player31/12/200516/6/2026
Stack-based buffer overflow in an ActiveX control for the installer for Adobe Macromedia Shockwave Player 10.1.0.11 and earlier allows remote attackers to execute arbitrary code via crafted large values for unspecified parameters.
ModificadaAlta (7.5)1.6%—Arcowave Systems Wlan AP + Adsl Router14/5/200516/6/2026
Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell.
ModificadaMedia (5)3.7%—Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security+631/12/200416/6/2026
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface.
ModificadaMedia (5)3.2%—Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security 320+831/12/200416/6/2026
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file.
ModificadaMedia (5)3.9%—Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security 320+831/12/200416/6/2026
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a…
ModificadaMedia (5)1.9%—Macromedia Flash PlayerMacromedia Shockwave22/4/200316/6/2026
Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).
ModificadaAlta (7.5)3.2%—Macromedia Shockwave Flash12/8/200216/6/2026
The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than the specified length.
ModificadaMedia (6.4)0.68%—CMG Openwave WAP Gateway31/12/200116/6/2026
Openwave WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.
ModificadaCrítica (9.8)1.9%—Lightwavemo Consoleserver 3200 Firmware2/7/200116/6/2026
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
ModificadaMedia (5)2.1%—Lightwave Consoleserver2/7/200116/6/2026
The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.
ModificadaAlta (7.6)1.7%—Macromedia Shockwave Flash Plugin26/3/200116/6/2026
Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file.
ModificadaMedia (5)2.9%💥 ExploitUnify Ewave Servletexec9/1/200116/6/2026
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".
ModificadaMedia (5)0.80%—Lucent WavelanOrinoco Wavelan1/1/200116/6/2026
Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages.
ModificadaMedia (5)8.5%💥 ExploitUnify Ewave Servletexec11/12/200016/6/2026
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.
ModificadaAlta (10)5.1%—Unify Ewave Servletexec11/12/200023/9/2026
eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.
ModificadaAlta (7.5)2.3%—Unify Ewave Servletexec8/6/200016/6/2026
Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
ModificadaMedia (5)1.1%—Macromedia Shockwave Flash Plugin11/3/199916/6/2026
Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.
ModificadaMedia (5.1)1.2%—Macromedia Shockwave Flash Plugin14/3/199716/6/2026
Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.
Orbitaley — Vulnerabilidades