Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)12%💥 ExploitFreewebshop10/11/200616/6/2026
Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773.
ModificadaMedia (6.1)2.0%💥 ExploitFreewebshop10/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
ModificadaMedia (5)7.9%💥 ExploitFreewebshop6/11/200616/6/2026
Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the installation path via a .. (dot dot) in the action parameter.
ModificadaAlta (7.5)1.2%💥 ExploitFreewebshop6/11/200616/6/2026
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) prod parameter.
ModificadaMedia (5.1)2.6%💥 ExploitCardway Digitalwebshop23/9/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _PHPLIB[libdir] parameter to (1) rechnung.php or (2) prepend.php.
ModificadaMedia (4.3)1.2%—Apt-webshop-system11/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject arbitrary web script or HTML via the message parameter, probably involving the basket functionality.
ModificadaMedia (5)1.2%—Apt-webshop-system11/4/200616/6/2026
Unspecified vulnerability in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to access unspecified files via a modified warp parameter.
ModificadaAlta (7.5)1.1%💥 ExploitApt-webshop-system11/4/200616/6/2026
Multiple SQL injection vulnerabilities in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allow remote attackers to execute arbitrary SQL commands via the (1) group, (2) seite, and (3) id parameter, possibly involving the artikel functionality. NOTE: this vulnerability also allows resultant path…
ModificadaAlta (10)6.1%—Mcafee Webshield Smtp4/4/200616/6/2026
Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed.
ModificadaMedia (4.6)0.40%—Twofold Photos Webshots Desktop31/12/200216/6/2026
Webshots Desktop screensaver allows local users to bypass the password on the screensaver by pressing CTRL-ALT-DELETE and (1) hitting the cancel button or (2) killing the screensaver from the task manager.
ModificadaAlta (7.5)6.7%—GFI MailsecurityNetwork Associates Webshield SmtpRoaring Penguin CanitRoaring Penguin Mimedefang+124/9/200216/6/2026
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly")…
ModificadaMedia (5)13%💥 ExploitBbshareware.com Phusion Webserver31/5/200216/6/2026
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.
ModificadaMedia (5)8.8%💥 ExploitBbshareware.com Phusion Webserver31/5/200216/6/2026
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.
ModificadaAlta (7.5)2.8%—Network Associates Webshield Smtp31/12/200116/6/2026
NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allow remote attackers to bypass filtering and possibly execute arbitrary code in email clients that process the invalid attachments.
ModificadaAlta (7.5)5.7%—Mcafee Webshield SmtpNetwork Associates Gauntlet FirewallPGP E-ppliance 300SGI Irix+14/9/200116/6/2026
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.
ModificadaAlta (7.5)3.3%—IcecastLibshout12/3/200116/6/2026
Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.
ModificadaAlta (7.5)1.5%—Network Associates Webshield Smtp9/1/200116/6/2026
McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.
ModificadaMedia (5)2.5%💥 ExploitNetwork Associates Webshield Smtp9/1/200116/6/2026
McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.
ModificadaMedia (5)1.7%—Network Associates Webshield Smtp20/10/200016/6/2026
WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.
ModificadaAlta (10)5.9%💥 ExploitNetwork Associates Gauntlet FirewallNetwork Associates WebshieldNetwork Associates Webshield E-ppliance18/5/200016/6/2026
Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands.
ModificadaAlta (7.5)3.5%—Network Associates Webshield1/5/200016/6/2026
Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service.
ModificadaMedia (5)2.4%—Network Associates Webshield1/5/200016/6/2026
The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command.
Orbitaley — Vulnerabilidades