Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomtraders COM Allcinevid | 20/1/2011 | 16/6/2026 | SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | |
| Modificada | Alta (7.8) | 3.0% | 💥 Exploit | Camtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-200 | 17/11/2010 | 16/6/2026 | The web server on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to cause a denial of service (device reboot) via a large number of requests in a short time interval. | |
| Modificada | Alta (10) | 9.4% | 💥 Exploit | Camtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-200 | 17/11/2010 | 16/6/2026 | The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a default password of m for the root account, and a default password of merlin for the mg3500 account, which makes it easier for remote attackers to obtain access via the TELNET… | |
| Modificada | Alta (10) | 4.2% | 💥 Exploit | Camtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-200 | 17/11/2010 | 16/6/2026 | The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to bypass authentication via a // (slash slash) at the beginning of a URI, as demonstrated by the //system.html URI. | |
| Modificada | Alta (7.8) | 16% | 💥 Exploit | Camtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-200 | 17/11/2010 | 16/6/2026 | Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Camtron Cmnc-200 FirmwareCamtron Cmnc-200Tecvoz Cmnc-200 FirmwareTecvoz Cmnc-200 | 17/11/2010 | 16/6/2026 | Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to execute arbitrary code via a long string in the first argument to the connect method. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Comtrend Ct-507it Adsl Router | 2/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | COM Joomtracker | 6/2/2009 | 16/6/2026 | SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php. | |
| Modificada | Media (6.8) | 4.7% | — | Matt Kimball AND Roger Wolff MTR | 21/5/2008 | 16/6/2026 | Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the ns_name_ntop function in resolv/ns_name.c… | |
| Modificada | Alta (7.8) | 1.5% | — | BEA Systems Aqualogic InteractionBEA Systems Plumtree Collaboration | 22/2/2008 | 16/6/2026 | Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL. | |
| Modificada | Media (4.3) | 1.2% | — | BEA Systems Aqualogic InteractionBEA Systems Plumtree Foundation | 21/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (5) | 1.4% | — | Cgi-club Imtrset | 5/7/2005 | 16/6/2026 | im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter. | |
| Modificada | Media (4.6) | 0.33% | — | MTR | 10/1/2005 | 16/6/2026 | Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator. | |
| Modificada | Media (5.8) | 2.2% | 💥 Exploit | Serena Software Serena Teamtrack | 31/12/2004 | 16/6/2026 | Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters. | |
| Modificada | Baja (2.1) | 0.50% | — | MTR | 12/8/2002 | 16/6/2026 | Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable. | |
| Modificada | Alta (7.5) | 1.6% | — | Plumtree Corporate Portal | 16/5/2002 | 16/6/2026 | Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter. | |
| Modificada | Alta (7.2) | 0.82% | 💥 Exploit | Matt Kimball AND Roger Wolff MTRTurbolinux | 3/3/2000 | 16/6/2026 | The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges. | |
| Modificada | Media (5) | 5.8% | 💥 Exploit | Teamshare Teamtrack | 1/10/1999 | 16/6/2026 | TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. |