Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.32%—Lenovo USB Enhanced Performance Keyboard16/4/201517/6/2026
Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.
ModificadaAlta (9.3)6.4%—Lenovo Thinkpad Bluetooth With Enhanced Data Rate Software21/1/201416/6/2026
Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed…
ModificadaMedia (4.3)4.6%—Microsoft Enhanced Mitigation Experience Toolkit29/11/201317/6/2026
Microsoft Enhanced Mitigation Experience Toolkit (EMET) before 4.0 uses predictable addresses for hooked functions, which makes it easier for context-dependent attackers to defeat the ASLR protection mechanism via a return-oriented programming (ROP) attack.
ModificadaMedia (6.8)1.1%💥 ExploitWilson Steven Mangosweb Enhanced9/10/201216/6/2026
SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php.
ModificadaAlta (9.3)4.1%—Ebay Enhanced Picture Uploader Activex Control9/6/200916/6/2026
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property.
ModificadaMedia (5)1.2%—Fujitsu Enhanced Support Facility10/3/200916/6/2026
The HRM-S service in Fujitsu Enhanced Support Facility 3.0 and 3.0.1 allows remote attackers to obtain (1) hardware and (2) software information via unspecified requests in a client connection.
ModificadaMedia (4.3)6.4%💥 ExploitSonicwall Sonicos Enhanced4/11/200816/6/2026
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled…
ModificadaAlta (7.5)0.97%💥 ExploitPhpauctions Phpauction GPL Enhanced6/8/200816/6/2026
SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)4.6%—Ebay Enhanced Picture Services8/7/200616/6/2026
Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Item (SYI), Setup & Test eBay Enhanced Picture Services, Picture Manager Enhanced Uploader, and CARad.com Add Vehicle, allows remote attackers to execute arbitrary code via a crafted…
ModificadaMedia (5)1.5%—Enhanced Simple PHP Gallery7/1/200616/6/2026
Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.
ModificadaMedia (4.3)1.3%—Enhanced Simple PHP Gallery7/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
ModificadaMedia (4.3)1.8%💥 ExploitSearch Enhanced30/10/200516/6/2026
Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
ModificadaMedia (5)0.89%—Phrozensmoke Gyach Enhanced31/12/200416/6/2026
Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.
ModificadaAlta (7.5)2.4%—Phrozensmoke Gyach Enhanced31/12/200416/6/2026
Buffer overflow in the strip_html_tags method for Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors involving HTML tags.
ModificadaAlta (7.5)2.9%—Phrozensmoke Gyach Enhanced31/12/200416/6/2026
Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) sending certain typing statuses or (2) setting the chat room status bar to the current chat room name.
ModificadaAlta (7.5)2.4%—Phrozensmoke Gyach Enhanced31/12/200416/6/2026
Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "avatar retrieval."
ModificadaMedia (5)1.1%—Phrozensmoke Gyach Enhanced31/12/200416/6/2026
Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.
ModificadaAlta (7.5)1.3%—Phrozensmoke Gyach Enhanced31/12/200416/6/2026
Multiple unspecified vulnerabilities in Gyach Enhanced (Gyach-E) before 1.0.5 have unknown impact and attack vectors related to "several security flaws," probably related to buffer overflows in HTTP server responses.
ModificadaMedia (5)1.2%—Phrozensmoke Gyach Enhanced31/12/200416/6/2026
Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to "URL data."
ModificadaAlta (10)3.8%—Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+1321/1/200416/6/2026
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
ModificadaMedia (5)2.4%—Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+1321/1/200416/6/2026
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.
ModificadaBaja (2.1)0.39%—NSA Security-enhanced Linux12/2/200116/6/2026
Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.
Orbitaley — Vulnerabilidades