Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.32% | — | Lenovo USB Enhanced Performance Keyboard | 16/4/2015 | 17/6/2026 | Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output. | |
| Modificada | Alta (9.3) | 6.4% | — | Lenovo Thinkpad Bluetooth With Enhanced Data Rate Software | 21/1/2014 | 16/6/2026 | Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed… | |
| Modificada | Media (4.3) | 4.6% | — | Microsoft Enhanced Mitigation Experience Toolkit | 29/11/2013 | 17/6/2026 | Microsoft Enhanced Mitigation Experience Toolkit (EMET) before 4.0 uses predictable addresses for hooked functions, which makes it easier for context-dependent attackers to defeat the ASLR protection mechanism via a return-oriented programming (ROP) attack. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Wilson Steven Mangosweb Enhanced | 9/10/2012 | 16/6/2026 | SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php. | |
| Modificada | Alta (9.3) | 4.1% | — | Ebay Enhanced Picture Uploader Activex Control | 9/6/2009 | 16/6/2026 | eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property. | |
| Modificada | Media (5) | 1.2% | — | Fujitsu Enhanced Support Facility | 10/3/2009 | 16/6/2026 | The HRM-S service in Fujitsu Enhanced Support Facility 3.0 and 3.0.1 allows remote attackers to obtain (1) hardware and (2) software information via unspecified requests in a client connection. | |
| Modificada | Media (4.3) | 6.4% | 💥 Exploit | Sonicwall Sonicos Enhanced | 4/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Phpauctions Phpauction GPL Enhanced | 6/8/2008 | 16/6/2026 | SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 4.6% | — | Ebay Enhanced Picture Services | 8/7/2006 | 16/6/2026 | Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Item (SYI), Setup & Test eBay Enhanced Picture Services, Picture Manager Enhanced Uploader, and CARad.com Add Vehicle, allows remote attackers to execute arbitrary code via a crafted… | |
| Modificada | Media (5) | 1.5% | — | Enhanced Simple PHP Gallery | 7/1/2006 | 16/6/2026 | Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message. | |
| Modificada | Media (4.3) | 1.3% | — | Enhanced Simple PHP Gallery | 7/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Search Enhanced | 30/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (5) | 0.89% | — | Phrozensmoke Gyach Enhanced | 31/12/2004 | 16/6/2026 | Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file. | |
| Modificada | Alta (7.5) | 2.4% | — | Phrozensmoke Gyach Enhanced | 31/12/2004 | 16/6/2026 | Buffer overflow in the strip_html_tags method for Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors involving HTML tags. | |
| Modificada | Alta (7.5) | 2.9% | — | Phrozensmoke Gyach Enhanced | 31/12/2004 | 16/6/2026 | Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) sending certain typing statuses or (2) setting the chat room status bar to the current chat room name. | |
| Modificada | Alta (7.5) | 2.4% | — | Phrozensmoke Gyach Enhanced | 31/12/2004 | 16/6/2026 | Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "avatar retrieval." | |
| Modificada | Media (5) | 1.1% | — | Phrozensmoke Gyach Enhanced | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages. | |
| Modificada | Alta (7.5) | 1.3% | — | Phrozensmoke Gyach Enhanced | 31/12/2004 | 16/6/2026 | Multiple unspecified vulnerabilities in Gyach Enhanced (Gyach-E) before 1.0.5 have unknown impact and attack vectors related to "several security flaws," probably related to buffer overflows in HTTP server responses. | |
| Modificada | Media (5) | 1.2% | — | Phrozensmoke Gyach Enhanced | 31/12/2004 | 16/6/2026 | Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to "URL data." | |
| Modificada | Alta (10) | 3.8% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. | |
| Modificada | Media (5) | 2.4% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning. | |
| Modificada | Baja (2.1) | 0.39% | — | NSA Security-enhanced Linux | 12/2/2001 | 16/6/2026 | Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory. |