Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 167 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
810 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Drunken Golem Gaming Portal | 30/1/2007 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en include/irc/phpIRC.php del Drunken:Golem Gaming Portal 0.5.1 Alpha 2 y versiones anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro phpbb_root_path. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Virtual Programming Vp-asp | 13/1/2007 | 16/6/2026 | Vulnerabilidad de inyección SQL en shopgiftregsearch.asp en VP-ASP Shopping Cart 6.09 y anteriores permite a atacantes remotos ejecutar comandos SQL a través del parámetro LoginLastname. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Virtual Programming Vp-asp | 13/1/2007 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en VP-ASP Shopping Cart 6.09 y anteriores permiten a un atacante remoto inyectar secuencias de comandos web o html a través del parámetro msg. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | MP3 Streaming Downsampler | 31/10/2006 | 16/6/2026 | Inclusión remota de archivo PHP en Core/core.inc.php en MP3 Streaming DownSampler (mp3SDS) 3.0, cuando está habilitado register_globals, permite a atacantes remotos ejecutar código PHP arbitrario a través del parámetro fullpath. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Invisionix Systems Invisionix Roaming System Remote | 21/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en pageheaderdefault.inc.php de Invisionix Roaming System Remote (IRSR) 0.2 y anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro _sysSessionPath. | |
| Modificada | Alta (7.5) | 2.8% | — | Gillius Programming Game Networking Engine | 27/7/2006 | 16/6/2026 | Vulnerabilidad de formato de cadena en la función flush_output en ConsoleStreambuf.cpp en Game Network Engine (GNE) 0.70 y anteriores permiten a atacantes remotos provocar denegación de servicio (caida) y posiblemente ejecutar código a través de formato de cadenas específicos en vectores no especificados afectando a… | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Virtual Programming Vp-asp | 9/5/2006 | 16/6/2026 | SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Mygamingladder | 25/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[base] parameter. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | GGZ Gaming Zone | 19/3/2006 | 16/6/2026 | GGZ Gaming Zone 0.0.12 allows remote attackers to cause a denial of service (client disconnect) via inputs that produce malformed XML, including (1) trailing ' (apostrophe) character on the ID attribute in a PLAYER XML tag, (2) joining with a long ID attribute or non-trailing ' characters, which causes a <none> name… | |
| Modificada | Baja (3.5) | 1.1% | — | Hummingbird Enterprise Collaboration | 11/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting. | |
| Modificada | Media (4) | 2.8% | 💥 Exploit | Hummingbird CollaborationHummingbird Enterprise Collaboration | 11/1/2006 | 16/6/2026 | Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie. | |
| Modificada | Media (4) | 2.3% | 💥 Exploit | Hummingbird Enterprise Collaboration | 11/1/2006 | 16/6/2026 | Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Innovateware Sights N Sounds Streaming Media Server | 13/12/2005 | 16/6/2026 | Desbordamiento de búfer en MediaServerList.exe en Sights 'n Sounds Streaming Media Server 2.0.3.a permite a atacantes remotos causar una denegación de servicio (caída de aplicación) mediante una cadena de consulta larga. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Virtual Programming Vp-asp | 19/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Hummingbird Connectivity | 17/8/2005 | 16/6/2026 | Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user's password in the FTP profile, which allows attackers to gain privileges. | |
| Modificada | Media (5) | 1.6% | — | Apple Darwin Streaming Server | 18/7/2005 | 16/6/2026 | Apple Darwin Streaming Server 5.5 y anteriores permite que atacantes remotos causen una denegación de servicio (caída de la aplicación) mediante una URL con un nombre de fichero con extensión .cgi y nombre de dispositivo de MS-DOS (tal como AUX, CON, PRN, COM1, o LPT1). | |
| Modificada | Alta (10) | 1.4% | — | Flexcast Audio Video Streaming Server | 9/6/2005 | 16/6/2026 | Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors. | |
| Modificada | Media (5) | 47% | 💥 Exploit | Hummingbird Connectivity | 1/6/2005 | 16/6/2026 | Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of data to LPD (Lpdw.exe). | |
| Modificada | Media (5) | 1.3% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 10/1/2005 | 16/6/2026 | Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte. | |
| Modificada | Baja (2.1) | 0.33% | — | Hummingbird Exceed | 31/12/2004 | 16/6/2026 | Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab. | |
| Modificada | Media (5) | 1.8% | — | Virtual Programming Vp-asp | 31/12/2004 | 16/6/2026 | shoprestoreorder.asp in VP-ASP 5.0 does not close the database connection when a user restores a previous order, which allows remote attackers to cause a denial of service (connection consumption). | |
| Modificada | Alta (7.5) | 1.2% | — | Virtual Programming Vp-asp | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitrary SQL commands via the catalogid parameter in (1) shopreviewlist.asp and (2) shopreviewadd.asp. | |
| Modificada | Media (4.4) | 0.36% | — | Hummingbird Connectivity | 31/12/2004 | 16/6/2026 | Inetd32 Administration Tool of Hummingbird Connectivity 7.1 and 9.0 allows local users to execute arbitrary code by changing the program for handling incoming connections. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Virtual Programming Vp-asp | 31/12/2004 | 16/6/2026 | The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site scripting (XSS) attacks that do not use <script> tags, as demonstrated via javascript in IMG tags to (1) the cat parameter in… | |
| Modificada | Baja (3.5) | 1.3% | — | Hummingbird Connectivity | 31/12/2004 | 16/6/2026 | Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a denial of service (application crash) via a long argument to the XCWD command. |