Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
1209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 1.1% | — | Index Data APS Keystone Digital Library Suite | 2/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Keystone Digital Library Suite (DLS) 1.5.4 and earlier allow remote attackers to execute arbitrary SQL commands via the subject_type_id parameter in (1) the index page and (2) the search module. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Digital Builder NZ Ecommerce | 9/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a… | |
| Modificada | Media (4.3) | 1.3% | — | Digital Builder NZ Ecommerce | 9/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem | |
| Modificada | Media (4.6) | 0.32% | — | Trust Digital Trusted Mobility SuiteAI | 31/12/2005 | 16/6/2026 | Trusted Mobility Agent PC Policy in Trust Digital Trusted Mobility Suite provides a cancel button that bypasses the domain-authentication prompt, which allows local users to sync a handheld (PDA) device despite a policy setting that sync is unauthorized. | |
| Modificada | Alta (7.5) | 1.9% | — | Digital Scribe | 20/9/2005 | 16/6/2026 | SQL injection vulnerability in login.php in Digital Scribe 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Geovision Digital Surveillance System | 14/5/2005 | 16/6/2026 | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image. | |
| Modificada | Alta (7.5) | 1.1% | — | Geovision Digital Surveillance System | 14/5/2005 | 16/6/2026 | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0 uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via sniffing. | |
| Modificada | Media (5) | 1.5% | — | Wenig AND Spitzer-williams Showoff Digital Media Software | 14/5/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in ShowOff! 1.5.4 allow remote attackers to read arbitrary files via ".." sequences in arguments to the (1) ShowAlbum, (2) ShowVideo, or (3) ShowGraphic scripts. | |
| Modificada | Media (5) | 1.8% | — | Wenig AND Spitzer-williams Showoff Digital Media Software | 11/5/2005 | 16/6/2026 | ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083. | |
| Modificada | Alta (7.5) | 1.3% | — | Digitalhive | 2/5/2005 | 16/6/2026 | DigitalHive 2.0 allows remote attackers to re-install the product by directly accessing the install script. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Digitalhive | 23/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the mt parameter to the membres.php page or (2) the -afs-1- query string to the msg.php page. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Digital Illusions Battlefield 1942Digital Illusions Battlefield Vietnam | 10/1/2005 | 16/6/2026 | Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Digital Mappings Systems Pop3 Server | 31/12/2004 | 16/6/2026 | Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) username or (2) password. | |
| Modificada | Baja (2.1) | 0.34% | — | Keene Digital Media ServerAI | 31/12/2004 | 16/6/2026 | Keene Digital Media Server 1.0.2 allows local users to obtain usernames and passwords by reading the dmscore.db file on the local system. | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Engardelinux Guardian Digital WebtoolUserminWebmin | 3/3/2003 | 16/6/2026 | miniserv.pl en Webmin anterior a 1.070 y Usermin antes de 1.000 no maneja adecuadamente metacaractéres como avance de línea y retorno de carro (CRLF) en cadenas codificadas en Base-64 durante la autenticación básica, lo que permite a atacantes remotos suplantar un ID de sesión y ganar privilegios de root. | |
| Modificada | Media (5) | 1.4% | — | RCA Digital Cable Modem | 31/12/2002 | 16/6/2026 | RCA Digital Cable Modem DCM225 and DCM225E, and other modems that must conform to the Data-over-Cable Service Interface Specifications DOCSIS standard, uses the "public" community string for SNMP access, which allows remote attackers to read or write MIB information. | |
| Modificada | Media (5) | 1.8% | — | RCA Digital Cable Modem | 31/12/2002 | 16/6/2026 | The RCA Digital Cable Modems DCM225 and DCM225E allow remote attackers to cause a denial of service (modem device reset) by connecting to port 80 on the 10.0.0.0/8 device. | |
| Modificada | Baja (2.1) | 0.41% | — | Adobe Digital Editions | 4/10/2002 | 16/6/2026 | Adobe eBook Reader 2.1 and 2.2 allows a user to copy eBooks to other systems by using the backup feature, capturing the encryption Challenge, and using the appropriate hash function to generate the activation code. | |
| Modificada | Media (4.6) | 1.6% | 💥 Exploit | Adobe Digital Editions | 4/10/2002 | 16/6/2026 | Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key data files, performing the operations, and restoring the original data files. | |
| Modificada | Alta (7.2) | 0.46% | — | Digital OSF 1Digital Ultrix | 4/10/2002 | 16/6/2026 | Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable. | |
| Modificada | Alta (7.2) | 0.46% | — | Digital OSF 1 | 4/10/2002 | 16/6/2026 | Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter. | |
| Modificada | Alta (7.2) | 1.0% | 💥 Exploit | Compaq Tru64Digital OSF 1 | 4/10/2002 | 16/6/2026 | Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument. | |
| Modificada | Alta (7.5) | 1.7% | — | Intel High-bandwidth Digital Content Protection | 20/11/2001 | 16/6/2026 | Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication. | |
| Modificada | Alta (7.5) | 2.0% | — | Eeye Digital Security SecureiisEeye Digital Security Securells | 14/8/2001 | 16/6/2026 | eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be… |