Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.4% | — | Admidio | 5/3/2017 | 17/6/2026 | SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization. | |
| Modificada | Alta (9.3) | 5.7% | 💥 Exploit | Musanim Music Animation Machine Midi Player | 20/1/2011 | 16/6/2026 | Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a long line in a MIDI (.mid) file. | |
| Modificada | Alta (9.3) | 16% | 💥 Exploit | Musanim Music Animation Machine Midi Player | 20/1/2011 | 16/6/2026 | Stack-based buffer overflow in Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attackers to execute arbitrary code via a long line in a .mamx file. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Admidio | 24/11/2008 | 16/6/2026 | Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (5) | 1.4% | — | Midicart Software Midicart PHP Shopping Cart | 11/12/2006 | 16/6/2026 | viewcart in Midicart accepts negative numbers in the Qty (quantity) field, which allows remote attackers to obtain a smaller total price for a shopping cart. | |
| Modificada | Media (6.5) | 1.2% | — | Midicart Software Midicart PHP Shopping Cart | 11/12/2006 | 16/6/2026 | Unrestricted file upload vulnerability in admin/add.php in Midicart allows remote authenticated users to upload arbitrary .php files, and possibly other files, to the images/ directory under the web root. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Midicart Software Midicart ASP Plus Shopping CartMidicart Software Midicart ASP Shopping Cart | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to… | |
| Modificada | Media (4.6) | 1.1% | 💥 Exploit | Tuomas Airaksinen Midirecord | 31/7/2006 | 16/6/2026 | Buffer overflow in the daemon function in midirecord.cc in Tuomas Airaksinen Midirecord 2.0 allows local users to execute arbitrary code via a long command line argument (filename). NOTE: This may not be a vulnerability if Midirecord is not installed setuid. | |
| Modificada | Alta (7.5) | 3.7% | — | Abcmidi | 27/4/2006 | 16/6/2026 | Multiple buffer overflows in the abcmidi-yaps translator in abcmidi 20050101, and other versions, allow remote attackers to execute arbitrary code via crafted ABC music files that trigger the overflows during translation into PostScript. | |
| Modificada | Alta (7.5) | 1.3% | — | Midicart Software Midicart PHP Shopping Cart | 17/8/2005 | 16/6/2026 | SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands via the code_no parameter to (1) Item_Show.asp or (2) search_list.asp. | |
| Modificada | Alta (7.5) | 1.5% | — | Midicart Software Midicart PHP Shopping Cart | 11/5/2005 | 16/6/2026 | MidiCart PHP Shopping Cart allows remote attackers to obtain sensitive information via a direct request to (1) search_list.php, (2) item_list.php, or (3) item_show.php, which reveal the path in a PHP error message. | |
| Modificada | Media (6.8) | 3.0% | — | Midicart Software Midicart PHP Shopping Cart | 11/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MidiCart PHP Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) searchstring parameter to search_list.php or the (2) secondgroup or (3) maingroup parameters to item_list.php. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Midicart PHP Shopping CartAI | 11/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring parameter to search_list.php, the (2) maingroup or (3) secondgroup parameters to item_list.php, or (4) code_no parameter to item_show.php. | |
| Modificada | Alta (7.2) | 0.51% | — | PlaymidiMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server | 14/4/2005 | 16/6/2026 | Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Abcmidi | 10/1/2005 | 16/6/2026 | Multiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote attackers to execute arbitrary code via crafted ABC files. | |
| Modificada | Media (5) | 7.8% | 💥 Exploit | Coxco Support A-cartCoxco Support MetacartCoxco Support Midicart ASPCoxco Support Midicart ASP Maxi+3 | 11/4/2003 | 16/6/2026 | MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database. | |
| Modificada | Crítica (9.1) | 4.6% | 💥 Exploit | Midicart PHPMidicart PHP MaxiMidicart PHP Plus | 31/12/2002 | 16/6/2026 | MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php. | |
| Modificada | Media (5.1) | 1.8% | 💥 Exploit | Yamaha Midiplug | 2/11/1999 | 16/6/2026 | Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag. |