Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
816 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | Codemasters Toca Race Driver | 26/7/2005 | 16/6/2026 | Desbordamiento de búfer en Race Driver 1.20 y anteriores permite que atacantes remotos causen una denegación de servicio (caída de la aplicación) mediante un mensaje largo "nickname" o "chat". | |
| Modificada | Alta (7.5) | 1.5% | — | Woppoware Postmaster | 18/5/2005 | 16/6/2026 | Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Woppoware Postmaster | 18/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject arbitrary web script or HTML via the email parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Woppoware Postmaster | 18/5/2005 | 16/6/2026 | message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to bypass authentication by modifying the email parameter. | |
| Modificada | Media (5) | 1.7% | — | Woppoware Postmaster | 18/5/2005 | 16/6/2026 | The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames. | |
| Modificada | Alta (7.5) | 1.5% | — | APG Technology Classmaster | 14/5/2005 | 16/6/2026 | APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share. | |
| Modificada | Alta (7.5) | 1.5% | — | Webmasters-debutants WD Guestbook | 2/5/2005 | 16/6/2026 | Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php. | |
| Modificada | Media (5) | 1.6% | — | Webtoolmaster Software Winhki | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in WinHKI 1.4d allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a zip file. | |
| Modificada | Media (5) | 1.7% | — | Quicksilver Master OF Orion III | 31/12/2004 | 16/6/2026 | Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Quicksilver Master OF Orion IIIAI | 31/12/2004 | 16/6/2026 | Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow. | |
| Modificada | Alta (7.5) | 2.1% | — | Textor Webmasters Ltd. Listrec.pl | 11/9/2001 | 16/6/2026 | Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Webmaster Conferenceroom | 26/3/2001 | 16/6/2026 | WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone. | |
| Modificada | Media (5) | 1.3% | — | Kenny Carruthers Postmaster | 9/1/2001 | 16/6/2026 | PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Armada Design Master Index | 19/12/2000 | 23/9/2026 | Vulnerabilidad de salto de directorio en el script CGI search.cgi de Armada Master Index permite a atacantes remotos leer archivos arbitrarios mediante un ataque de '..' (punto punto) en el parámetro 'catigory'. | |
| Modificada | Alta (7.5) | 1.4% | — | Livingston Portmaster Portmaster | 30/6/1998 | 16/6/2026 | Livingston Portmaster routers running ComOS use the same initial sequence number (ISN) for TCP connections, which allows remote attackers to conduct spoofing and hijack TCP sessions. | |
| Modificada | Media (5) | 1.4% | — | Livingston Portmaster Portmaster | 1/10/1995 | 16/6/2026 | Livingston portmaster machines could be rebooted via a series of commands. |