Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
–

816 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.4%—Codemasters Toca Race Driver26/7/200516/6/2026
Desbordamiento de búfer en Race Driver 1.20 y anteriores permite que atacantes remotos causen una denegación de servicio (caída de la aplicación) mediante un mensaje largo "nickname" o "chat".
ModificadaAlta (7.5)1.5%—Woppoware Postmaster18/5/200516/6/2026
Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm parameter.
ModificadaMedia (6.8)1.1%—Woppoware Postmaster18/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject arbitrary web script or HTML via the email parameter.
ModificadaAlta (7.5)1.5%—Woppoware Postmaster18/5/200516/6/2026
message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to bypass authentication by modifying the email parameter.
ModificadaMedia (5)1.7%—Woppoware Postmaster18/5/200516/6/2026
The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
ModificadaAlta (7.5)1.5%—APG Technology Classmaster14/5/200516/6/2026
APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.
ModificadaAlta (7.5)1.5%—Webmasters-debutants WD Guestbook2/5/200516/6/2026
Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.
ModificadaMedia (5)1.6%—Webtoolmaster Software Winhki2/5/200516/6/2026
Directory traversal vulnerability in WinHKI 1.4d allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a zip file.
ModificadaMedia (5)1.7%—Quicksilver Master OF Orion III31/12/200416/6/2026
Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail.
ModificadaMedia (5)3.5%💥 ExploitQuicksilver Master OF Orion IIIAI31/12/200416/6/2026
Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow.
ModificadaAlta (7.5)2.1%—Textor Webmasters Ltd. Listrec.pl11/9/200116/6/2026
Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter.
ModificadaMedia (5)7.1%💥 ExploitWebmaster Conferenceroom26/3/200116/6/2026
WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone.
ModificadaMedia (5)1.3%—Kenny Carruthers Postmaster9/1/200116/6/2026
PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.
ModificadaMedia (5)7.9%💥 ExploitArmada Design Master Index19/12/200023/9/2026
Vulnerabilidad de salto de directorio en el script CGI search.cgi de Armada Master Index permite a atacantes remotos leer archivos arbitrarios mediante un ataque de '..' (punto punto) en el parámetro 'catigory'.
ModificadaAlta (7.5)1.4%—Livingston Portmaster Portmaster30/6/199816/6/2026
Livingston Portmaster routers running ComOS use the same initial sequence number (ISN) for TCP connections, which allows remote attackers to conduct spoofing and hijack TCP sessions.
ModificadaMedia (5)1.4%—Livingston Portmaster Portmaster1/10/199516/6/2026
Livingston portmaster machines could be rebooted via a series of commands.