Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)60%💥 ExploitPmail Mercury Mail Transport System10/3/200716/6/2026
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command. NOTE: this might be the same issue as CVE-2006-5961.
ModificadaAlta (10)45%—HP Mercury Loadrunner AgentHP Mercury Monitor Over FirewallHP Mercury Performance Center Agent8/2/200716/6/2026
Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in…
ModificadaAlta (7.5)2.2%💥 ExploitPegasus Mercury Mail Transport System17/11/200616/6/2026
Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally reported in a GLEG VulnDisco pack. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The original researcher is reliable.
ModificadaMedia (4)1.5%—HP Mercury Sitescope3/10/200616/6/2026
Mercury SiteScope 8.2 (8.1.2.0) allows remote authenticated users to cause a denial of service (loss of connectivity to the classic interface) via attempted HTML injection into the "new monitor description" field.
ModificadaMedia (4.9)1.2%—HP Mercury Sitescope3/10/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Mercury SiteScope 8.2 (8.1.2.0) allow remote authenticated users to inject arbitrary web script or HTML via (1) "any field create name field" except "create new group name" or (2) any description field.
ModificadaBaja (2.1)0.33%—Mercury Messenger18/7/200616/6/2026
Mercury Messenger, possibly 1.7.1.1 and other versions, when running on a multi-user Mac OS X platform, stores chat logs with world-readable permissions within the /Users directory, which allows local users to read the chat logs from other users.
ModificadaAlta (7.5)65%💥 ExploitDavid Harris Mercury Mail Transport System20/12/200516/6/2026
Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105.
ModificadaMedia (4.3)0.94%—TMC Visionpool Mercury CMS20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters.
ModificadaAlta (7.5)1.2%—TMC Visionpool Mercury CMS20/12/200516/6/2026
SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModificadaAlta (7.5)2.1%💥 ExploitMercuryboard Message Board21/6/200516/6/2026
SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
ModificadaAlta (7.5)1.8%—Mercuryboard2/5/200516/6/2026
SQL injection vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary SQL commands via the f parameter.
ModificadaMedia (4.3)0.94%—Mercuryboard2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.
ModificadaMedia (5)1.5%—Mercuryboard2/5/200516/6/2026
index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.
ModificadaAlta (7.5)1.4%💥 ExploitMercuryboard27/4/200516/6/2026
SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.
ModificadaMedia (4.3)1.2%—Mercuryboard Message Board23/3/200516/6/2026
Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).
ModificadaMedia (4.3)0.94%—Mercuryboard17/2/200516/6/2026
Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.
ModificadaMedia (5)1.4%—Mercuryboard25/1/200516/6/2026
MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message.
ModificadaMedia (4.3)1.7%💥 ExploitMercuryboard25/1/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.
ModificadaAlta (10)72%💥 ExploitDavid Harris Mercury10/1/200516/6/2026
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME,…
ModificadaAlta (7.5)5.3%💥 ExploitDavid Harris Mercury NLM27/6/200116/6/2026
Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.
ModificadaAlta (10)3.1%—ApplesharePmail Mercury Mail ServerSeattlelab Slmail1/4/199816/6/2026
Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.
Orbitaley — Vulnerabilidades