Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.64%—Miura Ubercart Bulk Stock Updater17/9/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.
ModificadaAlta (9.3)2.0%—Datev Grundpaket Basis7/9/201216/6/2026
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 allow local users to gain privileges via a Trojan horse (1) DVBSKNLANG101.dll or (2) DvZediTermSrvInfo004.dll file in the current working directory, as demonstrated by a directory…
ModificadaMedia (4.3)2.7%💥 ExploitDatemill Etano6/9/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) email, (3) email2, (4) f17_zip, or (5) agree parameter to join.php; (6) PATH_INFO, (7) st, (8) f17_city, (9) f17_country, (10) f17_state, (11) f17_zip, (12)…
ModificadaMedia (6.9)0.35%—Symantec Liveupdate Administrator22/6/201216/6/2026
Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.
ModificadaBaja (2.1)0.35%—Gnome Update-manager-coreCanonical Ubuntu Linux7/6/201216/6/2026
DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials.
ModificadaMedia (6.8)27%💥 ExploitCraig Peterson Turbopower AbbreviaScadatec ModbustagserverScadatec Scadaphone3/4/201216/6/2026
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file.
ModificadaMedia (5)60%💥 ExploitVmware Vcenter Update Manager19/11/201116/6/2026
The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.
ModificadaAlta (10)65%💥 ExploitScadatec Procyon Scada15/9/201116/6/2026
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password to the Telnet (TCP/23) port, which triggers an out-of-bounds read or write, leading to a…
ModificadaMedia (4.3)4.2%💥 ExploitSymantec Liveupdate Administrator28/3/201116/6/2026
Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web script or HTML via the username field, as demonstrated by injecting an IFRAME element into the event log, a different vulnerability than…
ModificadaMedia (6.8)2.9%💥 ExploitSymantec Liveupdate Administrator28/3/201116/6/2026
Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts, and possibly have unspecified other impact, via the userRole parameter.
ModificadaAlta (10)4.6%—Creative Autoupdate Engine Activex ControlCreative Autoupdate15/6/201016/6/2026
Stack-based buffer overflow in Creative Software AutoUpdate Engine ActiveX Control 2.0.12.0, as used in Creative Software AutoUpdate 1.40.01, allows remote attackers to execute arbitrary code via vectors related to the BrowseFolder method.
ModificadaMedia (5)10%💥 ExploitSoftware.realtyna COM Joomlaupdater8/4/201016/6/2026
Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
ModificadaMedia (6.8)2.3%💥 ExploitSkadate Online Dating Software26/3/201016/6/2026
PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language_id parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.
ModificadaMedia (5.1)2.6%💥 ExploitTufat Osdate23/3/201016/6/2026
Multiple PHP remote file inclusion vulnerabilities in osDate 2.1.9 and 2.5.4, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[forum_installed] parameter to (1) forum/adminLogin.php and (2) forum/userLogin.php. NOTE: some of…
ModificadaMedia (5)2.8%💥 ExploitSkadate Online Dating Software15/3/201016/6/2026
Directory traversal vulnerability in index.php in SkaDate Dating allows remote attackers to read arbitrary files via a .. (dot dot) in the layout parameter.
ModificadaMedia (4.3)3.4%💥 ExploitSkadate Online Dating Software15/3/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in SkaDate Dating allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/auth.php and (2) file_uploader.php.
ModificadaAlta (10)6.0%—Datev Base System26/2/201016/6/2026
The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary commands via unspecified vectors.
ModificadaMedia (4.3)1.8%💥 ExploitDatemill24/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) return parameter to photo_view.php, and st parameter to (2) photo_search.php and (3) search.php.
ModificadaMedia (4.3)1.6%💥 ExploitDatetopia Match Agency BIZ24/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.
ModificadaMedia (4.3)1.5%💥 ExploitDatetopia BUY Dating Site24/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inject arbitrary web script or HTML via the s_r parameter.
ModificadaAlta (7.5)1.0%💥 ExploitFanupdate23/9/200916/6/2026
SQL injection vulnerability in show-cat.php in FanUpdate 2.2.1 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.
ModificadaBaja (2.1)1.2%—DrupalKaren Stevenson Date10/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or "administer content types" privileges, to inject arbitrary web script or HTML via a "Content type label" field.
ModificadaMedia (6.8)0.91%💥 ExploitIfusionservices Ifdate28/8/200916/6/2026
SQL injection vulnerability in members_search.php in iFusion Services iFdate 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the name field.
ModificadaAlta (7.5)1.00%💥 ExploitWEB Design Hero Joomladate10/2/200916/6/2026
SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php.
ModificadaAlta (9.3)1.6%—Acresso Flexnet ConnectAcresso Intallshield Update Agent18/9/200816/6/2026
Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules.
Orbitaley — Vulnerabilidades