Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 12 respecto a la semana anterior
Críticas / altas1272▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

844 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.1%—Pablo Software Solutions Baby ASP WEB ServerPablo Software Solutions Quick AND Easy WEB Server25/3/200616/6/2026
The (a) Quick 'n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extension of a URL.
ModificadaMedia (6.8)6.0%—Apple ItunesApple Quicktime19/3/200616/6/2026
Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPix (FPX) image that contains a field that specifies a large number of blocks.
ModificadaMedia (4.3)1.4%—JL Webworks Quickblogger31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) author ("your name") and (2) "comment" section.
ModificadaAlta (7.5)26%💥 ExploitApple Quicktime31/12/200516/6/2026
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.
ModificadaAlta (7.5)3.2%—Apple Quicktime31/12/200516/6/2026
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.
ModificadaAlta (7.5)8.6%—Apple Quicktime31/12/200516/6/2026
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a GIF image file with a crafted Netscape Navigator Application Extension Block that modifies the heap in the Picture Modifier block.
ModificadaAlta (7.5)4.0%—Apple Quicktime31/12/200516/6/2026
Integer underflow in Apple Quicktime before 7.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Color Map Entry Size in a TGA image file.
ModificadaMedia (5)1.4%—THE PHP Group Pear Html Quickform Controller31/12/200516/6/2026
The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors.
ModificadaAlta (7.5)4.1%—Apple Quicktime31/12/200516/6/2026
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values.
ModificadaAlta (7.5)7.3%—Apple Quicktime31/12/200516/6/2026
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags.
ModificadaAlta (7.5)8.0%—Apple Quicktime31/12/200516/6/2026
Buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.
ModificadaMedia (4.3)1.2%—Quicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.
ModificadaAlta (7.5)1.2%💥 ExploitQuicksquare Development Honeycomb ArchiveQuicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
ModificadaMedia (4.3)1.3%—Quickpaypro15/12/200516/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en QuickPayPro 3.1 permiten a atacantes remotos inyectar 'script' web o HTML de su elección mediante varios campos, como aquellos en (1) communication/subscribers.tracking.add.php, (2) support/tickets.add.php, y (3) mycompany/categories.php.
ModificadaAlta (7.5)4.7%💥 ExploitQuickpaypro15/12/200516/6/2026
Múltiples vulnerabilidades de inyección de SQL en QuickPayPro 3.1 permiten a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro (1) popupid en popups.edit.php; los parámetros (2) so, (3) sb, y (4) nr) en customer.tickets.view.php; el parámetro (5) subrackingid en subscribers.tracking.edit.php;…
ModificadaAlta (7.5)8.8%—Apple ItunesApple Quicktime8/12/200516/6/2026
Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified…
ModificadaMedia (5.1)1.1%—Quicksilver Forums6/12/200516/6/2026
SQL injection vulnerability in Quicksilver Forums before 1.5.1 allows remote attackers to execute arbitrary SQL commands via the HTTP_USER_AGENT header.
ModificadaAlta (7.5)1.5%—Coastal Data Management E-quick Cart22/11/200516/6/2026
Múltiples vulnerabilidades de inyección de SQL en e-Quick Cart permiten a atacantes remotos ejecutar comandos SQL de su elección mediante (1) el parámetro "productid" en shopaddtocart.asp, (2) el parámetro "strpemail" en shopprojectlogin.asp, y (3) el parámetro "id" en shoptellafriend.asp.
ModificadaMedia (4.3)1.3%—Coastal Data Management E-quick Cart22/11/200516/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en e-Quick Cart permiten a atacantes remotos inyectar 'script' web arbitrario o HTML mediante (1) el parámetro "strgifttoname" en shopgift.asp, (2) el parámetro "strfirstname" shopmaillist.asp, (3) el parámetro "strpid" en…
ModificadaMedia (4.3)1.2%💥 ExploitSymantec Veritas Cluster ServerSymantec Veritas Sanpoint Control QuickstartSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System16/11/200516/6/2026
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog,…
ModificadaMedia (5.1)2.1%—Apple Quicktime5/11/200516/6/2026
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."
ModificadaMedia (5.1)4.2%—Apple Quicktime5/11/200516/6/2026
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
ModificadaBaja (2.6)1.8%—Apple Quicktime5/11/200516/6/2026
Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.
ModificadaMedia (5.1)2.1%—Apple Quicktime5/11/200516/6/2026
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.
ModificadaMedia (5)7.8%—CAT Quick Heal1/11/200516/6/2026
Multiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by…
Orbitaley — Vulnerabilidades