Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.6) | 0.52% | — | Cspan Capture-tiny | 6/10/2014 | 17/6/2026 | The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a temporary file. | |
| Modificada | Alta (9.3) | 3.5% | — | IBM Datacap Taskmaster Capture | 21/3/2014 | 17/6/2026 | Stack-based buffer overflow in the Taskmaster Capture ActiveX control in IBM Datacap Taskmaster Capture 8.0.1, and 8.1 before FP2, allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5) | 1.5% | — | Bryce Hamrick Janrain Capture | 27/6/2012 | 16/6/2026 | The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks. | |
| Modificada | Media (5.8) | 2.3% | — | Bryce Hamrick Janrain Capture | 27/6/2012 | 16/6/2026 | Open redirect vulnerability in the Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when synchronizing user data, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Leadcapturepagesystem Lead Capture Page System | 29/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (5) | 1.4% | — | IBM Datacap Taskmaster Capture | 16/5/2011 | 16/6/2026 | The eDocument Conversion Actions implementation in IBM Datacap Taskmaster Capture 8.0.1 FP1 and earlier allows remote attackers to cause a denial of service (batch abort) via a long subject line in an e-mail message that is represented in a .eml file. | |
| Modificada | Media (6.8) | 1.2% | — | IBM Datacap Taskmaster Capture | 16/5/2011 | 16/6/2026 | IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an incorrect password in conjunction with an account name from a different domain. | |
| Modificada | Media (5) | 0.89% | — | IBM Datacap Taskmaster Capture | 16/5/2011 | 16/6/2026 | The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Datacap Taskmaster Capture | 16/5/2011 | 16/6/2026 | SQL injection vulnerability in TMWeb in IBM Datacap Taskmaster Capture 8.0.1 before FP1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 1.5% | — | Phpspot PHP & CSS BBSPhpspot PHP BBSPhpspot PHP BBS CEPhpspot PHP Image Capture BBS+2 | 22/9/2009 | 16/6/2026 | Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Phpspot PHP & CSS BBSPhpspot PHP BBSPhpspot PHP BBS CEPhpspot PHP Image Capture BBS+2 | 22/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to cookies. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Eeye Digital Security IrisSpynet Capturenet | 20/10/2000 | 16/6/2026 | eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections. |