Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 2.5% | — | Sielcosistemi Winlog PROSielcosistemi Winlog Lite | 19/8/2012 | 16/6/2026 | Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 do not validate the return value of the realloc function, which allows remote attackers to cause a denial of service (invalid 0x00 write operation and daemon crash) or possibly have unspecified other impact via a port-46824 TCP packet… | |
| Modificada | Alta (9.3) | 7.4% | 💥 Exploit | Sielcosistemi Winlog PROSielcosistemi Winlog Lite | 19/8/2012 | 16/6/2026 | Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbitrary code by referencing, within a port-46824 TCP packet, an invalid file-pointer index that leads to execution of an EnterCriticalSection code block. | |
| Modificada | Media (4.3) | 27% | 💥 Exploit | Sielcosistemi Winlog PROSielcosistemi Winlog Lite | 19/8/2012 | 16/6/2026 | Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a file-open operation with opcode 0x78 and a .. (dot dot) in a pathname, followed by a file-read… | |
| Modificada | Alta (9.3) | 8.2% | 💥 Exploit | Sielcosistemi Winlog PROSielcosistemi Winlog Lite | 19/8/2012 | 16/6/2026 | TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a port-46824 TCP packet with a crafted negative integer after the opcode, triggering incorrect function-pointer processing that can lead to a buffer overflow.… | |
| Modificada | Alta (9.3) | 8.2% | 💥 Exploit | Sielcosistemi Winlog PROSielcosistemi Winlog Lite | 19/8/2012 | 16/6/2026 | TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote attackers to execute arbitrary code via a port-46824 TCP packet with a crafted positive integer after the opcode, triggering incorrect function-pointer processing that can lead to a buffer overflow.… | |
| Modificada | Alta (9.3) | 25% | 💥 Exploit | Sielcosistemi Winlog PROSielcosistemi Winlog Lite | 19/8/2012 | 16/6/2026 | Stack-based buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote attackers to execute arbitrary code via a crafted port-46824 TCP packet that triggers an incorrect file-open attempt by the _TCPIPS_BinOpenFileFP function, a different… | |
| Modificada | Alta (9.3) | 44% | 💥 Exploit | Sielcosistemi Winlog LiteSielcosistemi Winlog PRO | 27/6/2012 | 16/6/2026 | Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 46824. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 4.5% | — | Sielcosistemi Winlog LiteSielcosistemi Winlog PRO | 22/12/2011 | 16/6/2026 | Buffer overflow in Sielco Sistemi Winlog PRO before 2.07.09 and Winlog Lite before 2.07.09 allows user-assisted remote attackers to execute arbitrary code via invalid data in unspecified fields of a project file. | |
| Modificada | Media (4.3) | 1.4% | — | CA Siteminder | 8/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.fcc in CA SiteMinder R6 SP6 before CR7 and R12 SP3 before CR8 allows remote attackers to inject arbitrary web script or HTML via the postpreservationdata parameter. | |
| Modificada | Media (4.3) | 2.4% | — | Broadcom SiteminderCA Siteminder | 27/4/2011 | 16/6/2026 | The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data. | |
| Modificada | Alta (9.3) | 40% | 💥 Exploit | Sielcosistemi Winlog PRO | 20/1/2011 | 16/6/2026 | Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted 0x02 opcode to TCP port 46823. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Iskenderaltuntas OTO Galeri Sistemi | 29/12/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Oto Galeri Sistemi 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) arac parameter to carsdetail.asp and the (2) marka parameter to twohandscars.asp. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Datemill | 24/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) return parameter to photo_view.php, and st parameter to (2) photo_search.php and (3) search.php. | |
| Modificada | Media (4.3) | 4.4% | 💥 Exploit | SUN J2eeBroadcom Siteminder | 11/8/2009 | 16/6/2026 | CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Aspindir Iltaweb Alisveris Sistemi | 24/12/2008 | 16/6/2026 | SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the catno parameter. | |
| Modificada | Media (6.9) | 0.36% | — | Dann Frazier Systemimager-server | 18/11/2008 | 16/6/2026 | si_mkbootserver in systemimager-server 3.6.3 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.inetd.conf or (2) /tmp/pxe.conf.*.tmp temporary file. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Broadcom Etrust Siteminder | 10/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in CA (formerly Computer Associates) eTrust SiteMinder Agent allows remote attackers to inject arbitrary web script or HTML via the SMAUTHREASON parameter, a different vector than CVE-2005-2204. | |
| Modificada | Alta (7.5) | 1.3% | — | Suskunduygular Uyelik Sistemi | 31/7/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in unuttum.asp in SuskunDuygular Uyelik Sistemi 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) kadi or (2) email parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.3% | — | Zindizayn Okul WEB Sistemi | 11/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Zindizayn Okul Web Sistemi 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) pass parameter to (a) mezungiris.asp or (b) ogretmenkontrol.asp. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Kartli Alisveris Sistemi | 7/6/2007 | 16/6/2026 | SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote attackers to execute arbitrary SQL commands via the news_id parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Forsnet WEB Icerik Yonetim Sistemi | 30/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Okulsistem Okul WEB Otomasyon Sistemi | 18/1/2007 | 16/6/2026 | SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mint Haber Sistemi | 18/1/2007 | 16/6/2026 | SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Paristemi | 26/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the HTTP_DOCUMENT_ROOT parameter, a different vector than CVE-2006-6689. | |
| Modificada | Alta (7.5) | 1.3% | — | Paristemi | 21/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Paristemi 0.8.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the SERVER_DIRECTORY parameter to unspecified scripts, a different vector than CVE-2006-6739. NOTE: The provenance of this information is unknown; the details are obtained… |