Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.6)6.8%💥 ExploitReview-script.com Five Star Review Script19/6/200616/6/2026
Varias vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en 5 Star Review permiten a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) el parámetro sort en index2.php, (2) el parámetro item_id en report.php, (3) el parámetro SEARCH_TERM (que se trata del "cuadro de…
ModificadaMedia (5)1.8%—Speedproject SpeedcommanderSpeedproject SqueezSpeedproject Zipstar25/2/200616/6/2026
Directory traversal vulnerability in SpeedProject Squeez 5.1, as used in (1) ZipStar 5.1 and (2) SpeedCommander 11.01.4450, allows remote attackers to overwrite arbitrary files via unspecified manipulations in a (1) JAR or (2) ZIP archive.
ModificadaAlta (7.2)0.34%—Starforce Safe N SEC Personal + Anti-spyware23/2/200616/6/2026
Unquoted Windows search path vulnerability in (1) snsmcon.exe, (2) the autostartup mechanism, and (3) an unspecified installation component in StarForce Safe'n'Sec Personal + Anti-Spyware 2.0 and earlier, and possibly other StarForce Safe'n'Sec products, might allow local users to gain privileges via a malicious…
ModificadaMedia (5.1)4.0%—Njstar Chinese Word ProcessorNjstar Japanese Word Processor21/2/200616/6/2026
Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents.
ModificadaMedia (5)3.1%💥 ExploitEstara Softphone17/2/200616/6/2026
Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m…
ModificadaMedia (5)1.6%—Estara Softphone17/2/200616/6/2026
eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits.
ModificadaMedia (5)3.1%💥 ExploitEstara Softphone17/2/200616/6/2026
eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field.
ModificadaAlta (7.5)16%💥 ExploitEstara Softphone13/1/200616/6/2026
Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field in the SDP data of a SIP packet on UDP port 5060.
ModificadaMedia (4.3)1.2%—Starphire Technologies SitesageStarphire Technologies Sitesage-eeStarphire Technologies Sitesage-leStarphire Technologies Sitesage-sb+122/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Starphire SiteSage 5.0.18 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the norelay_highlight_words parameter.
ModificadaAlta (7.8)4.3%—Astaro Security Linux4/12/200516/6/2026
The Internet Key Exchange version 1 (IKEv1) implementation in Astaro Security Linux before 6.102 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory,…
ModificadaAlta (7.5)1.3%—Omnistar Interactive Omnistar Kbase29/11/200516/6/2026
Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_id and (3) id parameters in users/kb.php.
ModificadaAlta (7.5)1.2%—Omnistar Interactive Omnistar Live26/11/200516/6/2026
SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240.
ModificadaMedia (5.1)2.6%—Speedproject SpeedcommanderSpeedproject SqueezSpeedproject Zipstar26/11/200516/6/2026
Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a…
ModificadaAlta (7.5)1.5%—Utstarcom F1000 Voip Wifi Phone21/11/200516/6/2026
The telnet daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has a default username "target" and password "password", which allows remote attackers to gain full access to the system.
ModificadaAlta (7.5)2.2%—Utstarcom F1000 Voip Wifi Phone21/11/200516/6/2026
UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 does not allow users to disable access to (1) SNMP or (2) the rlogin port TCP 513, which allows remote attackers to exploit other vulnerabilities such as CVE-2005-3716, or execute arbitrary shell commands via rlogin, which does not require…
ModificadaAlta (7.5)1.6%—Utstarcom F1000 Wi-fi Firmware21/11/200516/6/2026
The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers to obtain sensitive information.
ModificadaMedia (4.3)1.2%💥 ExploitSymantec Veritas Cluster ServerSymantec Veritas Sanpoint Control QuickstartSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System16/11/200516/6/2026
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog,…
ModificadaMedia (5)1.3%—4D Webstar5/10/200516/6/2026
Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP clients on Mac OS X 10.4 Mail 2.
ModificadaMedia (5)1.8%—Astaro Security Linux28/9/200516/6/2026
Unspecified "PPTP Remote DoS Vulnerability" in Astaro Security Linux 4.027 allows attackers to cause a denial of service.
ModificadaBaja (2.1)0.81%—Astaro Security Linux30/8/200516/6/2026
Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a .. (dot dot) in the wfe_download parameter to index.fpl.
ModificadaMedia (5)1.7%—Astaro Security Linux30/8/200516/6/2026
The HTTP proxy in Astaro Security Linux 6.0 allows remote attackers to obtain sensitive information via an invalid request, which reveals a Proxy-authorization string in an error message.
ModificadaAlta (7.5)6.6%💥 ExploitAstaro Security Linux30/8/200516/6/2026
The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services.
ModificadaMedia (5)5.7%💥 Exploit4D Webstar11/5/200516/6/2026
Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL.
ModificadaMedia (5)4.3%💥 ExploitLucasarts Star Wars Jedi Knight Jedi Academy2/5/200516/6/2026
Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code via a long message using commands such as (1) say and (2) tell.
ModificadaMedia (5)2.6%—Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+62/5/200516/6/2026
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data.
Orbitaley — Vulnerabilidades