Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.33%—Cosmoshop2/9/200516/6/2026
cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information.
ModificadaAlta (7.5)1.1%—Etoshop Dynamic BIZ Website Builder Quickweb5/7/200516/6/2026
SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.
ModificadaAlta (7.5)3.7%—Adobe Creative SuiteAdobe PhotoshopAdobe Premiere13/6/200516/6/2026
Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administrator privileges.
ModificadaBaja (2.1)0.35%—Toshiba Acpi Flash Bios2/5/200516/6/2026
An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed. NOTE: it has been debated as to whether or not this issue poses a security vulnerability,…
ModificadaMedia (4.6)0.34%—Toshiaki Kanosue Htmlheadline14/4/200516/6/2026
htmlheadline anteriores a 21.8 permiten a usuarios locales sobreescribir ficheros de su elección mediante un ataque de enlaces simbólicos (symlink) en ficheros temporales.
ModificadaMedia (4.3)3.9%💥 ExploitFrenoshopAI31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
ModificadaMedia (4.6)0.40%—Gunnar Ritter OSH7/8/200316/6/2026
Desbordamientos de búfer en osh anteriores a 1.7-11 permite a usuarios locales ejecutar código arbitrario y evitar restricciones de shell mediante varibles de entorno largas o "redirecciones de ficheros" largas.
ModificadaAlta (7.5)1.6%—Caupo.net Cauposhop26/7/200216/6/2026
Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field.
ModificadaAlta (7.5)1.8%—Joshua Chamas Apache ASP11/7/200016/6/2026
The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.