Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

86 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Wizardmac Readstat22/5/201817/6/2026
sav_parse_machine_integer_info_record in spss/readstat_sav_read.c in libreadstat.a in ReadStat 0.1.1 has a memory leak related to an iconv_open call.
ModificadaCrítica (9.8)13%💥 ExploitAttribute Wizard Project Attribute Wizard10/5/201817/6/2026
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.
ModificadaMedia (6.1)0.65%—Steelcase Roomwizard Firmware15/2/201817/6/2026
RoomWizard before 4.4.x allows XSS via the HelpAction.action pageName parameter.
ModificadaMedia (5.3)1.1%—Steelcase Roomwizard Firmware15/2/201817/6/2026
RoomWizard before 4.4.x allows remote attackers to obtain potentially sensitive information about IP addresses via /getGroupTimeLineJSON.action.
ModificadaAlta (7.5)1.1%—Steelcase Roomwizard Firmware15/2/201817/6/2026
GroupViewProxyServlet in RoomWizard before 4.4.x allows SSRF via the url parameter.
ModificadaAlta (7.8)1.0%—Wizardmac Readstat14/1/201817/6/2026
libreadstat.a in WizardMac ReadStat 0.1.1 has a heap-based buffer over-read via an unterminated string.
ModificadaAlta (9.3)13%💥 ExploitSony Smartwi Connection UtillitySony Vaio Easy ConnectSony Vaio PC Wireless LAN WizardSony Vaio Wireless Wizard7/6/201216/6/2026
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and VAIO Easy Connect software 1.0.0 and 1.1.0 allow remote…
ModificadaAlta (7.5)2.3%—Polyvision Roomwizard FirmwarePolyvision Roomwizard12/1/201116/6/2026
The PolyVision RoomWizard with firmware 3.2.3 has a default password of roomwizard for the administrator account, which makes it easier for remote attackers to obtain console access via an HTTP session, a different vulnerability than CVE-2010-0214.
ModificadaMedia (5)1.9%—Polyvision Roomwizard FirmwarePolyvision Roomwizard12/1/201116/6/2026
The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the…
ModificadaMedia (5)2.5%—HP Insight Managed System Setup Wizard2/11/201016/6/2026
Unspecified vulnerability in HP Insight Managed System Setup Wizard before 6.2 allows remote attackers to read arbitrary files via unknown vectors.
ModificadaAlta (9.3)5.6%💥 ExploitUpredsun Subtitle Translation Wizard24/6/201016/6/2026
Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to execute arbitrary code via a crafted SRT file with a long line after a time range. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)5.6%💥 ExploitUpredsun Isharer File Sharing Wizard18/6/201016/6/2026
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a long HEAD request.
ModificadaAlta (9.3)28%💥 ExploitUpredsun Isharer File Sharing Wizard18/6/201016/6/2026
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Length header.
ModificadaAlta (7.5)8.9%💥 ExploitDionesoft COM Dioneformwizard25/5/201016/6/2026
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.
ModificadaMedia (4)2.2%💥 ExploitDatawizard Ftpxq Server5/10/200916/6/2026
DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command.
ModificadaAlta (9.3)33%💥 ExploitEdisys Ezip Wizard20/3/200916/6/2026
Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file.
ModificadaMedia (5)1.6%—Fujitsu Systemcastwizard Lite26/1/200916/6/2026
Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.
ModificadaAlta (10)5.5%—Fujitsu Systemcastwizard Lite26/1/200916/6/2026
Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to execute arbitrary code via a large PXE protocol request in a UDP packet.
ModificadaAlta (10)1.6%—Fujitsu Systemcastwizard Lite26/1/200916/6/2026
Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown impact and attack vectors.
ModificadaAlta (9.3)32%💥 ExploitHummingbird Deployment Wizard24/10/200816/6/2026
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the…
ModificadaAlta (9.3)11%💥 ExploitAnzio Print WizardAnzio WEB Print Object29/8/200816/6/2026
Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Print Wizard, allows remote attackers to execute arbitrary code via a long mainurl parameter.
ModificadaMedia (6.8)3.6%💥 ExploitProwizard 4 PC21/12/200716/6/2026
Multiple stack-based buffer overflows in ProWizard 4 PC (prowiz) 1.62 and earlier allow remote attackers to execute arbitrary code via a crafted file to the (1) AMOS-MusicBank, (2) FuzzacPacker, and (3) QuadraComposer rippers; and (4) have an unknown impact via a crafted file to the SkytPacker ripper.
ModificadaAlta (7.5)2.4%💥 ExploitDB Soft LAB Dewizardx16/5/200716/6/2026
The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote attackers to overwrite arbitrary files via the SaveToFile function.
ModificadaMedia (6.4)1.2%—Datawizard Ftpxq27/10/200616/6/2026
FtpXQ Server 3.0.1 installs with two default testing accounts, which allows remote attackers to read or write arbitrary files via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (5)3.5%💥 ExploitDatawizard Ftpxq27/10/200616/6/2026
FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command.
Orbitaley — Vulnerabilidades