Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)12%—HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension19/10/201116/6/2026
Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1225.
ModificadaAlta (10)12%—HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension19/10/201116/6/2026
Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1222.
ModificadaAlta (10)14%💥 ExploitCisco Tandberg EndpointCisco Tandberg Personal Video Unit SoftwareCisco Tandberg Personal Video Unit3/2/201116/6/2026
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified login method.
ModificadaAlta (9.3)20%💥 ExploitSymantec Sygate Personal Firewall16/6/201016/6/2026
Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrary code via a long third argument to the SetRegString method.
ModificadaAlta (7.5)0.98%💥 ExploitUiga Personal Portal13/4/201016/6/2026
SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)0.82%💥 ExploitKaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus 2009Kaspersky LAB Kaspersky Anti-virus 2010Kaspersky LAB Kaspersky Anti-virus Personal+329/12/200916/6/2026
Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to…
ModificadaMedia (4)2.4%💥 ExploitDxm2008 XM Easy Personal FTP Server29/11/200916/6/2026
XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or creating a large number of files or directories, then performing a LIST command.
ModificadaMedia (4)2.4%💥 ExploitDxmsoft XM Easy Personal FTP Server23/11/200916/6/2026
Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE command to one socket in conjunction with a DELE command to a second socket.
ModificadaMedia (5)7.6%💥 ExploitWebsense Email SecurityWebsense Personal Email Manager22/10/200916/6/2026
The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial of service (crash) by sending a HTTP GET request to TCP port 8181 and closing the socket before the service can send a response.
ModificadaMedia (4.3)3.5%💥 ExploitWebsense Personal Email ManagerWebsense Email Security22/10/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1) FileName, (2) IsolatedMessageID, (3) ServerName, (4) Dictionary, (5)…
ModificadaMedia (5)6.4%💥 ExploitDxmsoft XM Easy Personal FTP Server9/10/200916/6/2026
Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to the (1) LIST and (2) NLST commands, a differnt issue than CVE-2008-5626 and CVE-2006-5728.
ModificadaAlta (7.2)0.65%—Avira AntivirAvira Antivir PersonalAvira Antivir ProfessionalAvira Antivir Security Suite13/8/200916/6/2026
Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE allows local users to execute arbitrary code via a crafted IOCTL request that overwrites a kernel pointer.
ModificadaAlta (7.2)0.77%💥 ExploitTallemu Online Armor Personal Firewall AV+Tallemu Personal Firewall13/7/200916/6/2026
The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Personal Firewall 3.5 before 3.5.0.14, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\OAmon containing arbitrary kernel addresses, as demonstrated using the…
ModificadaMedia (4)0.97%—Mephisteus THE Personal Sticky Threads27/4/200916/6/2026
The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and pages of an arbitrary thread by toggling a personal sticky.
ModificadaMedia (5)2.6%💥 ExploitDonnafontenot Mycal Personal Events Calendar2/3/200916/6/2026
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to mycal.mdb.
ModificadaMedia (5)6.4%💥 ExploitVirusblokada Vba32 Personal Antivirus19/12/200816/6/2026
The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of service (memory corruption and application crash) via a malformed RAR archive.
ModificadaMedia (4)36%💥 ExploitDxmsoft XM Easy Personal FTP Server17/12/200816/6/2026
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument to the NLST command, as demonstrated by a -1 argument.
ModificadaMedia (5)2.6%💥 ExploitIwrite Nightfall Personal Diary16/12/200816/6/2026
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb.
ModificadaMedia (4.3)1.6%💥 ExploitIwrite Nightfall Personal Diary16/12/200816/6/2026
Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter and possibly other "login fields." NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)2.6%💥 ExploitPhlatline Personal Information Manager9/10/200816/6/2026
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter in an edit action.
ModificadaAlta (10)7.0%💥 ExploitPhlatline Personal Information Manager3/10/200816/6/2026
Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory.
ModificadaAlta (7.5)3.0%💥 ExploitPhlatline Personal Information Manager3/10/200816/6/2026
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords.
ModificadaMedia (4.3)1.6%💥 ExploitPhlatline Personal Information Manager3/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the date parameter in a new action.
ModificadaAlta (8.8)3.0%💥 ExploitPhlatline Personal Information Manager3/10/200816/6/2026
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter within a delfile action.
ModificadaAlta (7.2)0.42%—Broadcom Internet Security SuiteCA Host Based Intrusion Prevention SystemCA Internet Security Suite 2008CA Personal Firewall 2007+112/8/200816/6/2026
The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request.