Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.5% | — | Nokia Impact | 25/11/2019 | 17/6/2026 | Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution. | |
| Modificada | Media (5.3) | 0.98% | — | IBM Tivoli Netcool/impact | 22/11/2019 | 17/6/2026 | IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 166720. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Tivoli Netcool/impact | 22/11/2019 | 17/6/2026 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.16 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 166719. | |
| Modificada | Crítica (9.8) | 1.5% | — | Webimpacto Icommktconnector | 26/8/2019 | 17/6/2026 | The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php. | |
| Modificada | Alta (8) | 1.5% | — | IBM Tivoli Netcool/impact | 17/6/2019 | 17/6/2026 | IBM Tivoli Netcool/Impact 7.1.0 allows for remote execution of command by low privileged User. Remote code execution allow to execute arbitrary code on system which lead to take control over the system. IBM X-Force ID: 158094. | |
| Modificada | Alta (7.2) | 4.4% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (7.8) | 0.56% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Tivoli Netcool/impact | 8/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool/Impact 6.1.1 before 6.1.1.1-TIV-NCI-IF0001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.9) | 0.36% | — | Novadevelopement Photoimpact X3 | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in PhotoImpact X3 13.00.0000.0 allows local users to gain privileges via a Trojan horse bwsconst.dll file in the current working directory, as demonstrated by a directory that contains a .ufp or .ufo file. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Media (5) | 1.2% | — | Impactsoftcompany Adpeeps | 22/7/2010 | 16/6/2026 | index.php in AdPeeps 8.5d1 allows remote attackers to obtain sensitive information via (1) a view_adrates action with an invalid uid parameter, which reveals the installation path in an error message; or (2) an adminlogin action with a crafted uid parameter, which reveals the version number. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Impactsoftcompany Adpeeps | 22/7/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdPeeps 8.5d1 allow remote attackers to inject arbitrary web script or HTML via the (1) uid parameter, (2) uid parameter in a login_lookup action, (3) uid parameter in an adminlogin action, (4) campaignid parameter in a createcampaign action, (5) type… | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Impactfinancials Impact PDF Reader | 18/6/2010 | 16/6/2026 | Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Php-fusion Team Impact TI Blog System Module | 26/12/2008 | 16/6/2026 | SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Early Impact Product Cart | 3/8/2005 | 16/6/2026 | SQL injection vulnerability in viewPrd.asp in Product Cart 2.6 allows remote attackers to execute arbitrary SQL commands via the idcategory parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Early Impact Productcart Ecommerce | 16/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp. | |
| Modificada | Media (4.3) | 0.99% | — | Early Impact Productcart | 8/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Early Impact Productcart | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or resultCnt parameters to advSearch_h.asp, and possibly (2) the offset parameter to tarinasworld_butterflyjournal.asp. NOTE: it is possible that item (2) is the result of a typo or… | |
| Modificada | Media (4.3) | 1.4% | — | Early Impact Productcart | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to… | |
| Modificada | Media (4.3) | 1.8% | — | Early Impact Productcart | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Custva.asp in EarlyImpact ProductCart allows remote attackers to inject arbitrary Javascript via the redirectUrl parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Early Impact Productcart | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Early Impact Productcart | 31/12/2003 | 16/6/2026 | EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information via a direct request. | |
| Modificada | Alta (10) | 1.9% | — | Early Impact Productcart | 18/8/2003 | 16/6/2026 | Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp. | |
| Modificada | Media (6.8) | 3.3% | 💥 Exploit | Early Impact Productcart | 18/8/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter. |