Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.6%💥 ExploitLivecms20/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.
ModificadaAlta (7.5)2.4%💥 ExploitLivecms20/6/200716/6/2026
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrary PHP code by specifying a PHP file type in a parameter intended for "a small image" associated with an article.
ModificadaAlta (7.5)1.3%💥 ExploitLivecms20/6/200716/6/2026
SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (9.3)3.1%💥 ExploitLivecms20/6/200716/6/2026
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message.
ModificadaAlta (9.3)7.8%—Corel Activecgm Browser14/6/200716/6/2026
Multiple buffer overflows in acgm.dll in the Corel / Micrografx ActiveCGM Browser ActiveX control before 7.1.4.19 allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (6.5)1.3%—Activecampaign 1-2-all Broadcast Email11/5/200716/6/2026
Incomplete blacklist vulnerability in filemanager/browser/default/connectors/php/config.php in the FCKeditor module, as used in ActiveCampaign 1-2-All (aka 12All) 4.50 through 4.53.13, and possibly other products, allows remote authenticated administrators to upload and possibly execute .php4 and .php5 files via…
ModificadaMedia (5)3.6%💥 ExploitActivecalendar26/2/200716/6/2026
Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
ModificadaMedia (6.8)6.1%💥 ExploitActivecalendar26/2/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.
ModificadaAlta (7.5)3.2%💥 ExploitActivecampaign Knowledgebuilder15/11/200616/6/2026
PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131.
ModificadaMedia (4.6)2.1%—Adobe Livecycle Form Manager13/4/200616/6/2026
Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked "OBSOLETE" but the account is also active, within the authentication system.
ModificadaMedia (4.3)1.9%💥 ExploitActivecampaign Supporttrio29/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module.
ModificadaMedia (5)1.5%—Activecampaign Supporttrio29/3/200616/6/2026
ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category parameter to modules/KB/pdf.php, which leaks the path in an error message.
ModificadaAlta (7.5)1.5%—Activecampaign 1-2-allActivecampaign GeneralActivecampaign IsalientActivecampaign Knowledgebuilder+23/3/200616/6/2026
PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.
ModificadaMedia (4)2.9%—Hauri LivecallHauri VirobotHauri Vrazmain.dll31/12/200516/6/2026
Buffer overflow in the archive decompression library (vrAZMain.dll 5.8.22.137), as used in HAURI anti-virus products including (1) ViRobot Expert 4.0, (2) ViRobot Advanced Server, and (3) HAURI LiveCall, allows user-assisted attackers to execute arbitrary code via an ALZ archive containing a file with a long filename.
ModificadaAlta (7.5)1.2%—Activecampaign Supporttrio31/12/200516/6/2026
SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information is unknown because the source URL is not available; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.2%—Activecampaign Knowledgebuilder26/11/200516/6/2026
SQL injection vulnerability in index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter.
ModificadaMedia (5)1.6%—Activecampaign SupporttrioAI26/11/200516/6/2026
index.php in ActiveCampaign SupportTrio 1.4 and earlier allows remote attackers to read or include arbitrary files via the page parameter, possibly due to a directory traversal vulnerability.
ModificadaAlta (7.8)1.8%—Activecampaign Knowledgebuilder26/11/200516/6/2026
index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an invalid category parameter, which causes a large number of SQL queries to be processed.
ModificadaAlta (7.5)1.3%💥 ExploitActivecampaign 1-2-all Broadcast Email18/11/200516/6/2026
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.
ModificadaAlta (7.5)4.0%—Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server30/8/200516/6/2026
Stack-based buffer overflow in the ACE archive decompression library (vrAZace.dll) in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall, when compressed file scanning is enabled, allows remote attackers to execute arbitrary code via an ACE archive that contains a…
ModificadaMedia (5)3.5%—Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server23/8/200516/6/2026
Directory traversal vulnerability in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall allows remote attackers to overwrite arbitrary files via ".." sequences in filenames contained in (1) ACE, (2) ARJ, (3) CAB, (4) LZH, (5) RAR, (6) TAR and (7) ZIP files.
ModificadaMedia (4.3)1.7%💥 ExploitLiveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa.
ModificadaAlta (7.5)3.4%💥 ExploitActivecampaign Knowledgebuilder31/12/200316/6/2026
PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.
ModificadaAlta (7.5)4.3%—Critical Path Injoin Directory ServerCritical Path Livecontent Directory16/7/200116/6/2026
Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)5.3%—Critical Path Injoin Directory ServerCritical Path Livecontent Directory16/7/200116/6/2026
Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
Orbitaley — Vulnerabilidades