Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2744▼ 111 respecto a la semana anterior
Críticas / altas1254▼ 280 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

1236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.3%—SUN Java System Content Delivery Server9/1/200716/6/2026
Sun Java System Content Delivery Server 5.0 y 5.0 PU1 permite a atacantes remotos obtener información sensible sobre "detalles de contenido" a través de vectores no especificados.
ModificadaMedia (6.8)1.4%—PHP Live27/12/200616/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en PHP Live! 3.2.2 y anteriores permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro (1) search_string de (a) setup/transcripts.php, el parámetro (2) l de (b) index.php, el campo (3)…
ModificadaMedia (4.3)0.34%—Symantec Livestate Agent FOR Windows6/12/200616/6/2026
** IMPUGNADA ** Symantec LiveState 7.1 Agent para Windows permite a usuarios locales obtener privilegios parando el proceso shstart.exe y abriendo "Web Self-Service" de la barra de iconos del sistema, lo cual abrirá una ventana de navegación ejecutándose con privilegios elevados. NOTA: varios investigadores de…
ModificadaMedia (4.3)11%—Microsoft Windows Live Messenger4/12/200616/6/2026
Microsoft Windows Live Messenger 8.0 y versiones anteriores, cuando los emoticonos gestuales están habilitados, permite a atacantes remotos provocar una denegación de servicio (agotamiento de CPU) mediante una cadena larga compuesta de secuencias ":D", que son interpretadas como emoticonos.
ModificadaMedia (6.8)1.4%—Oliver22/11/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en loginform-inc.php de Oliver (anteriormente Webshare) 1.2.2 y anteriores, cuando register_globals está activado, permite a atacantes remotos ejecutar código PHP de su elección mediante un nombre de ruta UNC de recurso compartido o un nombre de ruta de archivo…
ModificadaAlta (7.5)1.2%—ASP Scripter Easy PortalASP Scripter Live Support16/11/200616/6/2026
Vulnerabilidad de inyección SQL en cpLogin.asp en ASP Scripter Easy Portal 1.4 y Live Support 1.3 permite a un atacante remotos ejecutar comandos SQL de su elección a través del parámetro Password.
ModificadaMedia (5)2.4%—SUN Java System Content Delivery Server25/8/200616/6/2026
Vulnerabilidad no especificada en Sun Java System Content Delivery Server 4.0, 4.1, y 5.0 permite a atacantes locales y remotos leer datos de archivos de su elección a través de vectores no especificados.
ModificadaAlta (7.5)8.3%💥 ExploitTurnkey WEB Tools PHP Live Helper10/8/200616/6/2026
Vulnerabilidad de inclusión de fichero PHP remoto en global.php en Turnkey Web Tools PHP Live Helper 2.0 y anteriores permite a atacantes remotos ejecutar código PHP arbitrario mediante una URL en el parámetro abs_path.
ModificadaAlta (7.5)16%💥 ExploitPHP Live28/7/200616/6/2026
Vulnerabilidad PHP de inclusión remota de archivo en OSI Codes PHP Live! 3.2.1 y anteriores permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro css_path en (1) help.php y (2) setup/header.php.
ModificadaMedia (5.1)6.8%—Microsoft Windows Live Messenger27/6/200616/6/2026
Desbordamiento de búfer basado en memoria dinámica (heap) en Windows Live Messenger v8.0, permite a atacantes asistidos por el usuario ejecutar código de su elección a través de un archivo de listas de contacto (.ctt) manipulado, lo que provoca un desbordamiento cuando el archivo es importado por el usuario.
ModificadaAlta (7.5)4.7%—Livedata Iccp Server19/5/200616/6/2026
Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.
ModificadaMedia (5.8)1.3%—Turnkey WEB Tools PHP Live Helper16/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in chat.php in PHP Live Helper allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter.
ModificadaAlta (7.5)1.2%—Ubertec Help Center Live26/4/200616/6/2026
Multiple SQL injection vulnerabilities in the osTicket module in Help Center Live before 2.1.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (6.8)0.39%—Symantec LiveupdateSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton Personal Firewall+219/4/200616/6/2026
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.
ModificadaMedia (4.6)2.1%—Adobe Livecycle Form Manager13/4/200616/6/2026
Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked "OBSOLETE" but the account is also active, within the authentication system.
ModificadaAlta (7.5)2.0%—Turnkey WEB Tools PHP Live Helper29/3/200616/6/2026
Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by…
ModificadaAlta (7.5)4.8%—Turnkey WEB Tools PHP Live Helper29/3/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php.
ModificadaMedia (4.3)1.3%—Xigla Absolute Live Support XE28/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field.
ModificadaMedia (4.3)1.3%—PHP Live24/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in status_image.php in PHP Live! 3.0 allows remote attackers to inject arbitrary web script or HTML via the base_url parameter.
ModificadaMedia (4.3)1.4%—Cynical Games Shoutlive1/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages.
ModificadaAlta (7.5)3.3%💥 ExploitCynical Games Shoutlive1/3/200616/6/2026
Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php.
ModificadaMedia (6.4)4.0%💥 ExploitPear Liveuser23/2/200616/6/2026
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot…
ModificadaAlta (10)19%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+3031/12/200516/6/2026
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
ModificadaMedia (5.8)4.1%💥 ExploitKayako Liveresponse31/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when entering a session or sending a message.
ModificadaMedia (6.4)1.5%—Kayako Liveresponse31/12/200516/6/2026
Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and other include scripts, which reveals the path in an error message.