Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

883 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.0%—Electronic Arts Nascar Racing6/7/200616/6/2026
Papyrus NASCAR Racing v4 4.1.3.1.6 y anteriores, 2002 Season v1.1.0.2 y anteriores y 2003 Season v1.2.0.1 y anteriores; permite a atacantes remotos provocar una denegación de servicio (consumo de la CPU) enviando un datagrama UDP vacío, el cuál no es descartado adecuadamente debido al uso del socket asíncrono FIONREAD.
ModificadaBaja (2.6)1.4%💥 ExploitPatronet CMS13/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote attackers to inject arbitrary web script or HTML via the URI.
ModificadaMedia (4.3)2.0%💥 ExploitKryptronic Clickcartpro16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.
ModificadaMedia (5)1.2%—Lantronix Securelinx11/7/200516/6/2026
Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.
ModificadaMedia (5)1.7%—Firefly Studios Stronghold 230/5/200516/6/2026
Firefly Studios Stronghold 2 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large size value for the nickname, which causes a memory allocation failure and generates an exception.
ModificadaMedia (5)1.6%—LG Electronics LG Mobile Phone2/5/200516/6/2026
LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI file.
ModificadaMedia (5.3)3.5%💥 ExploitArmagetronad ArmagetronArmagetronad Armagetron Advanced2/5/200516/6/2026
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.
ModificadaMedia (5)1.3%—ArmagetronArmagetron Advanced2/5/200516/6/2026
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data.
ModificadaMedia (5)3.2%💥 ExploitArmagetronArmagetron Advanced2/5/200516/6/2026
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket.
ModificadaBaja (2.1)1.9%💥 ExploitFreeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+731/12/200416/6/2026
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
ModificadaMedia (5)3.1%💥 ExploitConceptronic Cadslr1 Adsl Router31/12/200416/6/2026
The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username.
ModificadaMedia (5)3.8%💥 ExploitMonolith Productions Contract JackMonolith Productions NO ONE Lives Forever 2Monolith Productions Tron31/12/200416/6/2026
The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that…
ModificadaMedia (5.1)4.3%💥 ExploitElectronic Arts Need FOR Speed HOT Pursuit 231/12/200416/6/2026
Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.
ModificadaAlta (10)2.8%—Frees WANSuper Frees WANOpenswanStrongswan6/12/200416/6/2026
FreeS/WAN 1.x y 2.x, y otros productos relacionados, incluyendo superfreeswan 1.x, openswan 1.x anteriores a 1.0.6, openswan 2.x anteriores a 2.1.4 y strongSwan anteriores a 2.1.3 permite a atacantes remotos autenticarse usando certificados PKCS#7 falsificados en los que un certificado auto-firmado identifica a una…
ModificadaAlta (7.5)62%💥 ExploitElectronic Arts Medal OF Honor Allied Assault27/7/200416/6/2026
Desbordamiento de búfer en Medal of Honor (1) Allied Assault 1.11v9 y anteriores, (2) Breakthrough 2.40b y anteriores, and (3) Spearhead 2.15 y anteriores, cuando se juega en una red de área local, permite a atacantes remotos ejecutar código arbitrario mediante vectores como (1) la consulta getinfo, (2), el paquete…
ModificadaAlta (7.5)2.8%—Proxomitron Naoko31/12/200316/6/2026
Buffer overflow in Proxomitron Naoko 4.4 allows remote attackers to execute arbitrary code via a long request.
ModificadaAlta (7.5)4.5%💥 ExploitElectronic Arts Battlefield 194231/12/200316/6/2026
Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.
ModificadaAlta (7.5)5.6%💥 ExploitNokia Electronic Documentation6/10/200316/6/2026
Nokia Electronics Documentation (NED) 5.0 permite a atacantes remotos usar NED como un proxy HTTP abierto mediante una URL en el parámetro de localización, al que NED accede y devuelve al usuario.
ModificadaMedia (5)6.6%💥 ExploitNokia Electronic Documentation6/10/200316/6/2026
Nokia Electronics Documentation (NED) 5.0 permite a atacantes remotos obtener un listado de directorio de la raíz del web de WebLogic, y la ruta física del servidor NED, mediante una acción "retrieve" (obtener) con un parámetro de localización de . (dot).
ModificadaMedia (4.3)12%💥 ExploitNokia Electronic Documentation6/10/200316/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Nokia Electronics Documentation (NED) 5.0 permite a atacantes remotos ejecutar script web arbitrario y robar galletitas (cookies) mediante una URL al directorio docs/ que contenga el script.
ModificadaAlta (10)5.9%💥 ExploitCyberstrong Eshop7/8/200316/6/2026
Vulnerabilidad de inyección de SQL en Cyberstrong eShop 4.2 y anteriores permite a atacantes remotos robar información de autenticación y ganar privilegios mediante el parámetro ProductCode en (1) 10expand.asp, (2) 10browse.asp, y (3) 20review.asp.
ModificadaAlta (7.5)4.2%—Cistron Radius Daemon7/8/200316/6/2026
El demonio RADIUS Cistron (radiusd-cistron) 1.6.6 y anteriores permite a atacantes remotos causar una dengación de servicio y posiblemente ejecutar código arbitrario mediante un valor largo en el atributo NAS-Port, que es interpretado como un número negativo y causa un desbordamiento de búfer.
ModificadaMedia (5)1.3%—Kryptronic Clickcartpro31/12/200216/6/2026
ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
ModificadaAlta (7.5)8.5%—Ascend RadiusFreeradiusGNU RadiusIcradius+84/3/200216/6/2026
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data.
ModificadaMedia (5)5.4%—FreeradiusGNU RadiusIcradiusLivingston Radius+74/3/200216/6/2026
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
Orbitaley — Vulnerabilidades