Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 1.3% | — | Lenovo Thinkvantage System Update | 21/7/2008 | 16/6/2026 | The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM. | |
| Modificada | Baja (2.1) | 0.31% | — | No-ip Dynamic Update Client | 18/6/2008 | 16/6/2026 | No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values. | |
| Modificada | Alta (9.3) | 41% | 💥 Exploit | Creative Software Autoupdate Engine | 29/5/2008 | 16/6/2026 | Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder property value. | |
| Modificada | Media (6.8) | 6.9% | 💥 Exploit | HP Software Update | 21/5/2008 | 16/6/2026 | Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute arbitrary code via an absolute pathname in the first argument. | |
| Modificada | Media (6.8) | 4.7% | — | HP Software Update | 25/4/2008 | 16/6/2026 | Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Kingsoft Antivirus Online Update Module | 12/3/2008 | 16/6/2026 | Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to execute arbitrary code via a long argument to the SetUninstallName method. | |
| Modificada | Media (4.3) | 1.0% | — | Bosdev Bosdates | 8/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x allows remote attackers to inject arbitrary web script or HTML via (1) the type parameter in calendar.php and (2) the category parameter in calendar_search.php. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Media (4.6) | 0.50% | — | Lumension Security Patchlink UpdateNovell Zenworks Patch Management Update Agent | 31/1/2008 | 16/6/2026 | PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary… | |
| Modificada | Alta (7.8) | 8.5% | 💥 Exploit | Bitdefender Update Server | 23/1/2008 | 16/6/2026 | Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Osdate | 11/1/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter. | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Macrovision Update Service | 4/1/2008 | 16/6/2026 | Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute arbitrary code via a long string in the ProductCode argument (second argument) to the DownloadAndExecute method, a different vulnerability than CVE-2007-0321,… | |
| Modificada | Alta (9.3) | 16% | 💥 Exploit | HP Software Update | 20/12/2007 | 16/6/2026 | The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile… | |
| Modificada | Media (6.8) | 5.8% | 💥 Exploit | Datecomm Social Networking Script | 20/11/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Datecomm Social Networking Script | 15/11/2007 | 16/6/2026 | SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page. | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Macrovision Flexnet ConnectMacrovision Installshield 2008Macrovision Update Service | 2/11/2007 | 16/6/2026 | Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow. | |
| Modificada | Media (5) | 8.3% | 💥 Exploit | Skadate Online Dating Software | 9/10/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow remote attackers to read arbitrary files via a .. (dot dot) in the view_mode parameter to (1) featured_list.php and (2) online_list.php in member/. | |
| Modificada | Alta (10) | 5.5% | — | Macrovision Flexnet ConnectMacrovision Update Service | 6/6/2007 | 16/6/2026 | Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Mealex MY Datebook | 6/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter. | |
| Modificada | Alta (9.3) | 5.3% | — | Macrovision Flexnet ConnectMacrovision Update Service | 1/6/2007 | 16/6/2026 | The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method. | |
| Modificada | Alta (10) | 2.6% | — | Ifusionservices Ifdate | 16/5/2007 | 16/6/2026 | ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI. | |
| Modificada | Media (5) | 18% | 💥 Exploit | Apple Software Update | 29/1/2007 | 16/6/2026 | Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Php-update | 31/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) newmessage, (2) newname, (3) newwebsite, or (4) newemail parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Php-update | 31/12/2006 | 16/6/2026 | admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login action. | |
| Modificada | Media (6) | 1.9% | 💥 Exploit | Php-update | 31/12/2006 | 16/6/2026 | Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP scripts to the gfx/ and files/ directories via the userfile parameter. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Php-update | 20/12/2006 | 16/6/2026 | Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission… |