Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1225. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1222. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Cisco Tandberg EndpointCisco Tandberg Personal Video Unit SoftwareCisco Tandberg Personal Video Unit | 3/2/2011 | 16/6/2026 | The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified login method. | |
| Modificada | Alta (9.3) | 20% | 💥 Exploit | Symantec Sygate Personal Firewall | 16/6/2010 | 16/6/2026 | Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrary code via a long third argument to the SetRegString method. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Uiga Personal Portal | 13/4/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 0.82% | 💥 Exploit | Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus 2009Kaspersky LAB Kaspersky Anti-virus 2010Kaspersky LAB Kaspersky Anti-virus Personal+3 | 29/12/2009 | 16/6/2026 | Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to… | |
| Modificada | Media (4) | 2.4% | 💥 Exploit | Dxm2008 XM Easy Personal FTP Server | 29/11/2009 | 16/6/2026 | XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or creating a large number of files or directories, then performing a LIST command. | |
| Modificada | Media (4) | 2.4% | 💥 Exploit | Dxmsoft XM Easy Personal FTP Server | 23/11/2009 | 16/6/2026 | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE command to one socket in conjunction with a DELE command to a second socket. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Websense Email SecurityWebsense Personal Email Manager | 22/10/2009 | 16/6/2026 | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial of service (crash) by sending a HTTP GET request to TCP port 8181 and closing the socket before the service can send a response. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Websense Personal Email ManagerWebsense Email Security | 22/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1) FileName, (2) IsolatedMessageID, (3) ServerName, (4) Dictionary, (5)… | |
| Modificada | Media (5) | 6.4% | 💥 Exploit | Dxmsoft XM Easy Personal FTP Server | 9/10/2009 | 16/6/2026 | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to the (1) LIST and (2) NLST commands, a differnt issue than CVE-2008-5626 and CVE-2006-5728. | |
| Modificada | Alta (7.2) | 0.65% | — | Avira AntivirAvira Antivir PersonalAvira Antivir ProfessionalAvira Antivir Security Suite | 13/8/2009 | 16/6/2026 | Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE allows local users to execute arbitrary code via a crafted IOCTL request that overwrites a kernel pointer. | |
| Modificada | Alta (7.2) | 0.77% | 💥 Exploit | Tallemu Online Armor Personal Firewall AV+Tallemu Personal Firewall | 13/7/2009 | 16/6/2026 | The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Personal Firewall 3.5 before 3.5.0.14, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\OAmon containing arbitrary kernel addresses, as demonstrated using the… | |
| Modificada | Media (4) | 0.97% | — | Mephisteus THE Personal Sticky Threads | 27/4/2009 | 16/6/2026 | The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and pages of an arbitrary thread by toggling a personal sticky. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Donnafontenot Mycal Personal Events Calendar | 2/3/2009 | 16/6/2026 | MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to mycal.mdb. | |
| Modificada | Media (5) | 6.4% | 💥 Exploit | Virusblokada Vba32 Personal Antivirus | 19/12/2008 | 16/6/2026 | The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of service (memory corruption and application crash) via a malformed RAR archive. | |
| Modificada | Media (4) | 36% | 💥 Exploit | Dxmsoft XM Easy Personal FTP Server | 17/12/2008 | 16/6/2026 | XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument to the NLST command, as demonstrated by a -1 argument. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Iwrite Nightfall Personal Diary | 16/12/2008 | 16/6/2026 | Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Iwrite Nightfall Personal Diary | 16/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter and possibly other "login fields." NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Phlatline Personal Information Manager | 9/10/2008 | 16/6/2026 | Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter in an edit action. | |
| Modificada | Alta (10) | 7.0% | 💥 Exploit | Phlatline Personal Information Manager | 3/10/2008 | 16/6/2026 | Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Phlatline Personal Information Manager | 3/10/2008 | 16/6/2026 | changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Phlatline Personal Information Manager | 3/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the date parameter in a new action. | |
| Modificada | Alta (8.8) | 3.0% | 💥 Exploit | Phlatline Personal Information Manager | 3/10/2008 | 16/6/2026 | Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter within a delfile action. | |
| Modificada | Alta (7.2) | 0.42% | — | Broadcom Internet Security SuiteCA Host Based Intrusion Prevention SystemCA Internet Security Suite 2008CA Personal Firewall 2007+1 | 12/8/2008 | 16/6/2026 | The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request. |