Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

791 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.4%—THE PHP Group Pear Html Quickform Controller31/12/200516/6/2026
The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors.
ModificadaAlta (7.5)4.1%—Apple Quicktime31/12/200516/6/2026
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values.
ModificadaAlta (7.5)3.2%—Apple Quicktime31/12/200516/6/2026
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.
ModificadaAlta (7.5)26%💥 ExploitApple Quicktime31/12/200516/6/2026
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.
ModificadaAlta (7.5)7.3%—Apple Quicktime31/12/200516/6/2026
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags.
ModificadaAlta (7.5)8.0%—Apple Quicktime31/12/200516/6/2026
Buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.
ModificadaMedia (4.3)1.4%—JL Webworks Quickblogger31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) author ("your name") and (2) "comment" section.
ModificadaAlta (7.5)4.0%—Apple Quicktime31/12/200516/6/2026
Integer underflow in Apple Quicktime before 7.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Color Map Entry Size in a TGA image file.
ModificadaAlta (7.5)1.2%💥 ExploitQuicksquare Development Honeycomb ArchiveQuicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
ModificadaMedia (4.3)1.2%—Quicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.
ModificadaAlta (7.5)4.7%💥 ExploitQuickpaypro15/12/200516/6/2026
Múltiples vulnerabilidades de inyección de SQL en QuickPayPro 3.1 permiten a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro (1) popupid en popups.edit.php; los parámetros (2) so, (3) sb, y (4) nr) en customer.tickets.view.php; el parámetro (5) subrackingid en subscribers.tracking.edit.php;…
ModificadaMedia (4.3)1.3%—Quickpaypro15/12/200516/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en QuickPayPro 3.1 permiten a atacantes remotos inyectar 'script' web o HTML de su elección mediante varios campos, como aquellos en (1) communication/subscribers.tracking.add.php, (2) support/tickets.add.php, y (3) mycompany/categories.php.
ModificadaAlta (7.5)8.8%—Apple ItunesApple Quicktime8/12/200516/6/2026
Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified…
ModificadaMedia (5.1)1.1%—Quicksilver Forums6/12/200516/6/2026
SQL injection vulnerability in Quicksilver Forums before 1.5.1 allows remote attackers to execute arbitrary SQL commands via the HTTP_USER_AGENT header.
ModificadaMedia (4.3)1.3%—Coastal Data Management E-quick Cart22/11/200516/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en e-Quick Cart permiten a atacantes remotos inyectar 'script' web arbitrario o HTML mediante (1) el parámetro "strgifttoname" en shopgift.asp, (2) el parámetro "strfirstname" shopmaillist.asp, (3) el parámetro "strpid" en…
ModificadaAlta (7.5)1.5%—Coastal Data Management E-quick Cart22/11/200516/6/2026
Múltiples vulnerabilidades de inyección de SQL en e-Quick Cart permiten a atacantes remotos ejecutar comandos SQL de su elección mediante (1) el parámetro "productid" en shopaddtocart.asp, (2) el parámetro "strpemail" en shopprojectlogin.asp, y (3) el parámetro "id" en shoptellafriend.asp.
ModificadaMedia (4.3)1.2%💥 ExploitSymantec Veritas Cluster ServerSymantec Veritas Sanpoint Control QuickstartSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System16/11/200516/6/2026
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog,…
ModificadaMedia (5.1)2.1%—Apple Quicktime5/11/200516/6/2026
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."
ModificadaMedia (5.1)4.2%—Apple Quicktime5/11/200516/6/2026
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
ModificadaMedia (5.1)2.1%—Apple Quicktime5/11/200516/6/2026
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.
ModificadaBaja (2.6)1.8%—Apple Quicktime5/11/200516/6/2026
Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.
ModificadaMedia (5)7.8%—CAT Quick Heal1/11/200516/6/2026
Multiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by…
ModificadaAlta (7.5)4.7%—Apple QuicktimeApple MAC OS XApple MAC OS X Server26/10/200516/6/2026
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.
ModificadaMedia (5.1)14%—CAT Quick Heal14/10/200516/6/2026
Multiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected…
ModificadaMedia (5)3.7%💥 ExploitPablo Software Solutions Quick N Easy FTP Server5/8/200516/6/2026
Quick 'n Easy FTP Server 3.0 permite que atacantes remotos causen una denegación de servicio (caída de la aplicación o excesivo consumo de CPU) mediante un comando USER demasiado largo.
Orbitaley — Vulnerabilidades