Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
1046 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | ARI Pikivirta Home FTP Server | 30/8/2005 | 16/6/2026 | Home Ftp Server 1.0.7 stores sensitive user information and server information in the same directory as the user's home directory, which allows remote authenticated users to obtain sensitive information by obtaining ftpmembers.lst and ftpsettings.lst. | |
| Modificada | Baja (3.7) | 0.66% | — | GNU GzipFreebsdGentoo LinuxRedhat Enterprise Linux+9 | 2/5/2005 | 16/6/2026 | Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | All4www-homepagecreator | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute arbitrary PHP code by modifying the site parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (6.6) | 0.41% | — | Prevx Home | 10/1/2005 | 16/6/2026 | Prevx Home 1.0 allows local users with administrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalmemory, which restores the running kernel's original SDT ServiceTable. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | 2wire Homeportal | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU A2psTurbolinux HomeTurbolinux ServerTurbolinux Workstation | 27/12/2004 | 16/6/2026 | The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Media (5) | 17% | — | Apache Http ServerHP Secure WEB Server FOR Tru64Gentoo LinuxHp-ux+8 | 16/9/2004 | 16/6/2026 | The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access. | |
| Modificada | Alta (7.5) | 18% | 💥 Exploit | University OF California Seti AT Home | 31/12/2003 | 16/6/2026 | Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Easy Scripts Archive Advanced Easy Homepage CreatorEasy Scripts Archive Easy Homepage Creator | 11/4/2003 | 16/6/2026 | La función print_html_to_file en edit.cgi de Easy Homepage Creator 1.0 no comprueba credenciales de usuaurio, lo que permite a atacantes remotos modificar páginas de otros usuarios. | |
| Modificada | Media (5) | 1.9% | — | Alcatel Speed Touch Home | 25/3/2002 | 16/6/2026 | el modem de Alcatel Speed Touch Home ADSL permite e atacantes remotos causar una negación de servicio (reboot) via a scaneo de la red con paquetes anormales, como nmap con detección de OS | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Amtote Homebet | 31/12/2001 | 16/6/2026 | AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack. | |
| Modificada | Alta (7.8) | 0.41% | 💥 Exploit | Mckesson Pathways Homecare | 31/12/2001 | 16/6/2026 | Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file. | |
| Modificada | Media (4.6) | 0.40% | — | University OF California Seti AT Home | 31/12/2001 | 16/6/2026 | Buffer overflow in setiathome for SETI@home 3.03, if installed setuid, could allow local users to execute arbitrary code via long command line options (1) socks_server, (2) socks_user, and (3) socks_passwd. NOTE: since the default configuration of setiathome is not setuid, perhaps this issue should not be included in… | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Amtote International Homebet | 29/9/2001 | 16/6/2026 | AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal account and PIN numbers. | |
| Modificada | Alta (7.5) | 2.0% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations. | |
| Modificada | Alta (7.5) | 3.5% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 3.7% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Keware Technologies Homeseer | 16/2/2001 | 16/6/2026 | Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers. | |
| Modificada | Media (5.1) | 16% | 💥 Exploit | Microsoft Clip ARTMicrosoft GreetingsMicrosoft Home Publishing | 6/3/2000 | 16/6/2026 | Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | IBM Homepageprint | 2/11/1999 | 16/6/2026 | Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag. | |
| Modificada | Media (5) | 5.8% | 💥 Exploit | Solution Scripts Home Free | 3/1/1999 | 16/6/2026 | search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack. |