Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Laurent Foulloy SAV Filter ABC | 19/3/2010 | 16/6/2026 | SQL injection vulnerability in the SAV Filter Alphabetic (sav_filter_abc) extension before 1.0.9 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 2.3% | — | Zakkis ABC Advertise | 6/5/2009 | 16/6/2026 | Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator login name and password via a direct request. | |
| Modificada | Alta (7.5) | 2.4% | — | Arabcms | 22/10/2008 | 16/6/2026 | Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the rss parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Algera ABC Estore | 31/8/2007 | 16/6/2026 | SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Media (5) | 1.3% | — | Wabcms | 31/5/2007 | 16/6/2026 | WabCMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/wabcmsn.mdb. NOTE: this issue was originally reported for "webCMS," but this was an error by an unreliable researcher. | |
| Modificada | Alta (9.3) | 6.7% | — | Abc-view Manager | 26/4/2007 | 16/6/2026 | Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file. | |
| Modificada | Alta (7.5) | 3.7% | — | Abcmidi | 27/4/2006 | 16/6/2026 | Multiple buffer overflows in the abcmidi-yaps translator in abcmidi 20050101, and other versions, allow remote attackers to execute arbitrary code via crafted ABC music files that trigger the overflows during translation into PostScript. | |
| Modificada | Media (5.1) | 2.3% | — | Abc2ps | 25/4/2006 | 16/6/2026 | Multiple buffer overflows in abc2ps before 1.3.3 allow user-assisted attackers to execute arbitrary code via crafted ABC music files. | |
| Modificada | Alta (7.5) | 1.2% | — | Abczone.it Wwwguestbook | 3/5/2005 | 16/6/2026 | SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Alta (10) | 11% | — | Abctab2ps | 10/1/2005 | 16/6/2026 | Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow remote attackers to execute arbitrary code via crafted ABC files. | |
| Modificada | Alta (10) | 6.0% | — | Abc2psJohn Chambers Jcabc2ps | 10/1/2005 | 16/6/2026 | Buffer overflow in the switch_voice function in parse.c for jcabc2ps 20040902 allows remote attackers to execute arbitrary code via a crafted ABC file. | |
| Modificada | Alta (10) | 8.8% | — | Abcpp | 10/1/2005 | 16/6/2026 | Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via crafted ABC files. | |
| Modificada | Alta (10) | 6.0% | — | Moinejf Abcm2ps | 10/1/2005 | 16/6/2026 | Buffer overflow in the put_words function in subs.c for abcm2ps 3.7.20 allows remote attackers to execute arbitrary code via crafted ABC files. | |
| Modificada | Alta (10) | 6.0% | — | Abc2mtex | 10/1/2005 | 16/6/2026 | Buffer overflow in the process_abc function in abc.c for abc2mtex 1.6.1 allows remote attackers to execute arbitrary code via crafted ABC files. | |
| Modificada | Alta (10) | 10% | — | Abcmidi | 10/1/2005 | 16/6/2026 | Multiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote attackers to execute arbitrary code via crafted ABC files. | |
| Modificada | Media (5) | 1.5% | — | Abczone.it Wwwguestbook | 31/12/2004 | 16/6/2026 | Abczone.it WWWguestbook 1.1 stores db/dbase.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the plaintext username and password. |