Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 67% | — | HP Loadrunner | 29/7/2013 | 16/6/2026 | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1705. | |
| Modificada | Alta (7.5) | 6.3% | — | HP Loadrunner | 29/7/2013 | 16/6/2026 | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1690. | |
| Modificada | Alta (7.5) | 62% | — | HP Loadrunner | 29/7/2013 | 16/6/2026 | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1671. | |
| Modificada | Alta (7.5) | 5.5% | — | HP Loadrunner | 29/7/2013 | 16/6/2026 | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1670. | |
| Modificada | Media (5) | 9.6% | — | HP Loadrunner | 29/7/2013 | 16/6/2026 | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to cause a denial of service via unknown vectors, aka ZDI-CAN-1669. | |
| Modificada | Media (6.8) | 5.9% | — | HP Loadrunner | 2/6/2011 | 16/6/2026 | Buffer overflow in HP LoadRunner allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a .usr (aka Virtual User script) file with long directives. | |
| Modificada | Alta (10) | 13% | — | HP Loadrunner | 18/1/2011 | 16/6/2026 | Unspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, related to the HttpTunnel feature. | |
| Modificada | Alta (7.5) | 2.3% | — | HP Loadrunner WEB ToursHP Loadrunner | 28/10/2010 | 16/6/2026 | Unspecified vulnerability in LoadRunner Web Tours 9.10 in HP LoadRunner 9.1 and earlier allows remote attackers to cause a denial of service, and possibly obtain sensitive information or modify data, via unknown vectors. | |
| Modificada | Alta (10) | 78% | — | HP LoadrunnerHP Performance Center | 7/5/2010 | 16/6/2026 | Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9.3) | 42% | — | Persits XuploadHP Loadrunner | 13/10/2009 | 16/6/2026 | Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method. | |
| Modificada | Alta (7.5) | 1.9% | — | Xlinesoft Phprunner | 19/3/2009 | 16/6/2026 | UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication. | |
| Modificada | Alta (7.5) | 2.1% | — | Xlinesoft Phprunner | 19/3/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php. | |
| Modificada | Media (6.8) | 3.1% | — | Learn2 Strunner | 3/3/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the Learn2 Corporation STRunner (aka Street Technologies) ActiveX control in iestm32.dll allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.4) | 2.1% | — | Canon I-sensysCanon ImagepressCanon ImagerunnerCanon Imagerunner 2620+8 | 29/2/2008 | 16/6/2026 | The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce. | |
| Modificada | Alta (9.3) | 37% | — | Groove Virtual OfficeHP LoadrunnerPersits Xupload | 27/12/2007 | 16/6/2026 | Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function. | |
| Modificada | Alta (10) | 10% | — | Supportsoft ScriptrunnerSupportsoft SmartissueSymantec Automated Support AssistantSymantec Norton Antivirus+2 | 22/2/2007 | 16/6/2026 | Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message. | |
| Modificada | Alta (10) | 45% | — | HP Mercury Loadrunner AgentHP Mercury Monitor Over FirewallHP Mercury Performance Center Agent | 8/2/2007 | 16/6/2026 | Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in… | |
| Modificada | Baja (2.1) | 0.33% | — | Xlinesoft Phprunner | 17/11/2006 | 16/6/2026 | XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Media (4) | 1.1% | — | Canon Imagerunner 2620Canon Imagerunner 5020Canon Imagerunner 6870Canon Imagerunner 8500+3 | 11/9/2006 | 16/6/2026 | The Remote UI in Canon imageRUNNER includes usernames and passwords when exporting an address book, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.3% | — | Adsl Road Runner Modem | 8/9/2005 | 16/6/2026 | ADSL Road Runner modem in the Annex A family has a service running on port 224, which allows remote attackers to login to the modem with a blank password and gain unauthorized access. | |
| Modificada | Alta (7.5) | 1.5% | — | Xlinesoft Asprunner | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements. | |
| Modificada | Media (5) | 7.9% | — | Xlinesoft Asprunner | 31/12/2004 | 16/6/2026 | ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names. | |
| Modificada | Alta (7.5) | 1.6% | — | Canon Imagerunner 5000iCanon Imagerunner C3200 | 31/12/2004 | 16/6/2026 | The print-from-email feature in the Canon ImageRUNNER (iR) 5000i and C3200 digital printer, when not using IP address range filtering, allows remote attackers to print arbitrary text without authentication via a text/plain email to TCP port 25. | |
| Modificada | Media (5) | 8.8% | — | Xlinesoft Asprunner | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp. | |
| Modificada | Media (5) | 1.8% | — | Xlinesoft Asprunner | 31/12/2004 | 16/6/2026 | ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages. |