Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 18% | — | Adobe Flash PlayerAdobe Flex SDK | 12/9/2006 | 16/6/2026 | Desbordamiento de búfer en Adobe Flash Player 8.0.24.0 y anteriores, Flash Professional 8, Flash MX 2004, y Flex 1.5 permite a un atacante con la complicidad del usuario ejecutar código de su elección a través de una cadena grande y creada dinamicamente en una película SWF. | |
| Modificada | Media (5.8) | 2.0% | 💥 Exploit | Seyeon Flexwatch Network Camera | 18/7/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en index.php de FlexWATCH Network Camera 3.0 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante el URL. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Seyeon Flexwatch Network Camera | 18/7/2006 | 16/6/2026 | Vulnerabilidad de salto de directorio en FlexWATCH Network Camera 3.0 y anteriores permite a atacantes remotos evitar las restricciones de acceso para (1) admin/aindex.asp o (2) admin/aindex.html a través de la secuencia .. (punto punto) y codificar la secuencia / (%2f) en la URL. | |
| Modificada | Media (5.8) | 1.3% | — | Flexchat | 16/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in FlexChat 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) CFTOKEN parameter in (a) index.cfm and (3) CFTOKEN and (4) CFID parameter in (b) chat.cfm. | |
| Modificada | Media (5.8) | 1.3% | — | Lethal Penguin PassmasterflexLethal Penguin Passmasterflexplus | 12/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PassMasterFlex and PassMasterFlexPlus (PassMasterFlex+) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password, or (3) User-Agent HTTP header in the Hack Log. | |
| Modificada | Alta (7.5) | 2.0% | — | Flexcustomer | 9/5/2006 | 16/6/2026 | SQL injection vulnerability in FlexCustomer 0.0.4 and earlier allows remote attackers to bypass authentication and execute arbitrary SQL commands via the admin and ordinary user interface, probably involving the (1) checkuser and (2) checkpass parameters to (a) admin/index.php, and (3) username and (4) password… | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Flexbb | 26/4/2006 | 16/6/2026 | SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all usernames and passwords, via the id parameter to the showprofile page in index.php. | |
| Modificada | Media (5.8) | 1.2% | — | Flexbb | 21/4/2006 | 16/6/2026 | Vulnerabilidad de guiones en sitios cruzados (XSS) en FlexBB 0.5.7 BETA y anteriores permite a atacantes remotos inyectar guiones web o HTML de su elección mediante los parámetros (1) name y (2) message. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Flexbb | 21/4/2006 | 16/6/2026 | Vulnerabilidad de inyección de SQL en inc/start.php en FlexBB 0.5.5 y anteriores permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro 'cookie' flexbb_username. | |
| Modificada | Media (6.4) | 1.1% | — | Flexbb | 18/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) forumid, or (3) threadid parameter to index.php; the (4) ICQ, (5) AIM, (6) MSN, (7) Google Talk, (8) Website Name, (9) Website Address, (10) Email Address, (11) Location, (12)… | |
| Modificada | Baja (1.9) | 0.43% | — | Flexbb | 18/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to inject arbitrary web script or HTML via the (1) ICQ, (2) AIM, (3) MSN, (4) Google Talk, (5) Website Name, (6) Website Address, (7) Email Address, (8) Location, (9) Signature, and (10) Sub-Titles fields in the user… | |
| Modificada | Media (4.3) | 1.2% | — | Andries Bruinsma Flexible Development | 5/4/2006 | 16/6/2026 | Unspecified vulnerability in main.php in an unspecified "file created by Andries Bruinsma," possibly a FleXiBle Development (FXB) application, allows remote attackers to include and execute arbitrary PHP code. NOTE: this disclosure is extremely vague and has very little information about the specific vulnerability… | |
| Modificada | Alta (7.5) | 4.7% | — | Westes Flex | 29/3/2006 | 16/6/2026 | flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to… | |
| Modificada | Media (4.6) | 0.57% | — | Flexbackup | 31/12/2005 | 16/6/2026 | Flexbackup 1.2.1 and earlier allows local users to overwrite files and execute code via a symlink attack on temporary files. NOTE: the raw source referenced an incorrect candidate number; this is the correct number to use. | |
| Modificada | Alta (10) | 1.4% | — | Flexcast Audio Video Streaming Server | 9/6/2005 | 16/6/2026 | Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | China-on-site Flexphpnews | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter. | |
| Modificada | Alta (10) | 5.3% | 💥 Exploit | Seyeon Flexwatch Network Video Server | 30/10/2003 | 16/6/2026 | FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//). | |
| Modificada | Media (5) | 1.5% | — | Sapio Design LTD Webreflex | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request. | |
| Modificada | Alta (10) | 5.3% | — | Paul L Daniels InflexPaul L Daniels Ripmime | 16/5/2002 | 16/6/2026 | Desbordamiento de buffer en plDaniels ripMime 1.2.6 y anteriores, usados en programas como xamime y inflex, permiten a atacantes remotos ejecutar código arbitrario mediante un adjunto en un nombre de fichero largo. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Sapio Design LTD Webreflex | 3/5/2001 | 16/6/2026 | Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request. | |
| Modificada | Media (5) | 1.3% | — | Globetrotter Flexlm | 25/9/1998 | 16/6/2026 | The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command. | |
| Modificada | Alta (7.2) | 1.3% | 💥 Exploit | Globetrotter FlexlmSGI License OEOSGI IrixSUN Solaris+1 | 6/1/1997 | 16/6/2026 | Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX. |