Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)67%—HP Loadrunner29/7/201316/6/2026
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1705.
ModificadaAlta (7.5)6.3%—HP Loadrunner29/7/201316/6/2026
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1690.
ModificadaAlta (7.5)62%—HP Loadrunner29/7/201316/6/2026
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1671.
ModificadaAlta (7.5)5.5%—HP Loadrunner29/7/201316/6/2026
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1670.
ModificadaMedia (5)9.6%—HP Loadrunner29/7/201316/6/2026
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to cause a denial of service via unknown vectors, aka ZDI-CAN-1669.
ModificadaMedia (6.8)5.9%—HP Loadrunner2/6/201116/6/2026
Buffer overflow in HP LoadRunner allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a .usr (aka Virtual User script) file with long directives.
ModificadaAlta (10)13%—HP Loadrunner18/1/201116/6/2026
Unspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, related to the HttpTunnel feature.
ModificadaAlta (7.5)2.3%—HP Loadrunner WEB ToursHP Loadrunner28/10/201016/6/2026
Unspecified vulnerability in LoadRunner Web Tours 9.10 in HP LoadRunner 9.1 and earlier allows remote attackers to cause a denial of service, and possibly obtain sensitive information or modify data, via unknown vectors.
ModificadaAlta (10)78%—HP LoadrunnerHP Performance Center7/5/201016/6/2026
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (9.3)42%—Persits XuploadHP Loadrunner13/10/200916/6/2026
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.
ModificadaAlta (7.5)1.9%—Xlinesoft Phprunner19/3/200916/6/2026
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
ModificadaAlta (7.5)2.1%—Xlinesoft Phprunner19/3/200916/6/2026
Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.
ModificadaMedia (6.8)3.1%—Learn2 Strunner3/3/200816/6/2026
Multiple stack-based buffer overflows in the Learn2 Corporation STRunner (aka Street Technologies) ActiveX control in iestm32.dll allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (6.4)2.1%—Canon I-sensysCanon ImagepressCanon ImagerunnerCanon Imagerunner 2620+829/2/200816/6/2026
The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce.
ModificadaAlta (9.3)37%—Groove Virtual OfficeHP LoadrunnerPersits Xupload27/12/200716/6/2026
Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.
ModificadaAlta (10)10%—Supportsoft ScriptrunnerSupportsoft SmartissueSymantec Automated Support AssistantSymantec Norton Antivirus+222/2/200716/6/2026
Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.
ModificadaAlta (10)45%—HP Mercury Loadrunner AgentHP Mercury Monitor Over FirewallHP Mercury Performance Center Agent8/2/200716/6/2026
Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in…
ModificadaBaja (2.1)0.33%—Xlinesoft Phprunner17/11/200616/6/2026
XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.
ModificadaMedia (4)1.1%—Canon Imagerunner 2620Canon Imagerunner 5020Canon Imagerunner 6870Canon Imagerunner 8500+311/9/200616/6/2026
The Remote UI in Canon imageRUNNER includes usernames and passwords when exporting an address book, which allows context-dependent attackers to obtain sensitive information.
ModificadaAlta (7.5)1.3%—Adsl Road Runner Modem8/9/200516/6/2026
ADSL Road Runner modem in the Annex A family has a service running on port 224, which allows remote attackers to login to the modem with a blank password and gain unauthorized access.
ModificadaAlta (7.5)1.5%—Xlinesoft Asprunner31/12/200416/6/2026
SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.
ModificadaMedia (5)7.9%—Xlinesoft Asprunner31/12/200416/6/2026
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.
ModificadaAlta (7.5)1.6%—Canon Imagerunner 5000iCanon Imagerunner C320031/12/200416/6/2026
The print-from-email feature in the Canon ImageRUNNER (iR) 5000i and C3200 digital printer, when not using IP address range filtering, allows remote attackers to print arbitrary text without authentication via a text/plain email to TCP port 25.
ModificadaMedia (5)8.8%—Xlinesoft Asprunner31/12/200416/6/2026
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.
ModificadaMedia (5)1.8%—Xlinesoft Asprunner31/12/200416/6/2026
ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.