Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

729 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.6%—Cisco Callmanager Express9/8/200616/6/2026
Vulnerabilidad no especificada en Cisco IOS CallManager Express (CME) permite a atacantes remotos obtener información sensible (nombres de usuario) desde el directorio de usuarios SIP(Session Initiation Protocol) mediante ciertos mensajes SIP, también conocido como bug CSCse92417.
ModificadaAlta (7.5)1.1%💥 ExploitPHP Lite Calendar Express12/6/200616/6/2026
Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) catid and (2) cid parameter. NOTE: this might be a duplicate of CVE-2005-4009.c.
ModificadaBaja (2.1)1.6%—Cisco Unity Express SoftwareCisco Unity Express4/5/200616/6/2026
Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any user with an expired password.
ModificadaAlta (7.5)1.7%—Fileprotection Express4/5/200616/6/2026
FileProtection Express 1.0.1 and earlier allows remote attackers to bypass authentication via a cookie with an Admin value of 1.
ModificadaMedia (4.3)40%💥 ExploitMicrosoft Outlook Express1/5/200616/6/2026
A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain Information Disclosure Vulnerability."
ModificadaMedia (5.1)24%—Microsoft Outlook Express12/4/200616/6/2026
Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.
ModificadaMedia (4.3)1.2%—PHP Lite Calendar Express28/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (4.3)2.1%💥 ExploitPmachine Expressionengine27/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).
ModificadaMedia (5)3.0%—F-secure Anti-virusF-secure Internet SecurityF-secure Personal ExpressF-secure Internet Gatekeeper21/1/200616/6/2026
Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP…
ModificadaAlta (7.5)5.8%—F-secure Anti-virusF-secure Internet SecurityF-secure Internet GatekeeperSolutions Based ON F-secure Personal Express21/1/200616/6/2026
Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives.
ModificadaMedia (5)2.4%—Cisco Application AND Content Networking SoftwareCisco ATACisco Subscriber Edge Services ManagerCisco IP Phone 7902+331/12/200516/6/2026
Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect offset.
ModificadaMedia (5)1.7%—Apple Airport ExpressApple Airport Extreme31/12/200516/6/2026
The network interface for Apple AirPort Express 6.x before Firmware Update 6.3, and AirPort Extreme 5.x before Firmware Update 5.7, allows remote attackers to cause a denial of service (unresponsive interface) via malformed packets.
ModificadaMedia (4.3)12%—Microsoft Outlook Express Book Control31/12/200516/6/2026
The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, which is not intended for use within Internet Explorer.
ModificadaMedia (4.3)1.3%—Internet Express Products Commercesql16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in CommerceSQL 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keywords parameter in the Quick Find feature.
ModificadaAlta (7.5)1.4%—Sensation Designs Kbase Express5/12/200516/6/2026
SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to category.php and (2) search parameters to search.php.
ModificadaAlta (7.5)1.3%—PHP Lite Calendar Express5/12/200516/6/2026
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (b) week.php, (c) month.php, and (d) year.php.
ModificadaAlta (7.8)4.9%—Checkpoint Check PointCheckpoint ExpressCheckpoint Firewall-1Checkpoint Vpn-1+118/11/200516/6/2026
The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666,…
ModificadaMedia (5)2.3%—SUN Java System Communications Express3/11/200516/6/2026
Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files.
ModificadaAlta (7.5)1.8%—Rockliffe Mailsite Express2/11/200516/6/2026
Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions, such as (1) .unk, (2) .asa, and possibly (3) .htr and (4) .aspx, which are not filtered like the .asp extension.
ModificadaMedia (4.3)1.5%—Rockliffe Mailsite Express2/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to inject arbitrary web script or HTML via a message body.
ModificadaMedia (5)1.6%—Rockliffe Mailsite Express2/11/200516/6/2026
Absolute path traversal vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to read arbitrary files via a full pathname in the AttachPath field of a mail message under composition.
ModificadaMedia (4.3)2.4%—Rockliffe Mailsite Express2/11/200516/6/2026
Rockliffe MailSite Express before 6.1.22, with the option to save login information enabled, saves user passwords in plaintext in cookies, which allows local users to obtain passwords by reading the cookie file, or remote attackers to obtain the cookies via cross-site scripting (XSS) vulnerabilities.
ModificadaMedia (5)1.6%—Rockliffe Mailsite Express23/10/200516/6/2026
Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message.
ModificadaMedia (5)1.4%—Rockliffe Mailsite Express23/10/200516/6/2026
Incomplete blacklist vulnerability in Mailsite Express allows remote attackers to upload and possibly execute files via attachments with executable extensions such as ASPX, which are not converted to .TXT like other dangerous extensions, and which can be directly requested from the cache directory.
ModificadaMedia (5)13%—Microsoft Outlook Express12/7/200516/6/2026
Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.
Orbitaley — Vulnerabilidades