Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.6)0.52%—Cspan Capture-tiny6/10/201417/6/2026
The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a temporary file.
ModificadaAlta (9.3)3.5%—IBM Datacap Taskmaster Capture21/3/201417/6/2026
Stack-based buffer overflow in the Taskmaster Capture ActiveX control in IBM Datacap Taskmaster Capture 8.0.1, and 8.1 before FP2, allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (5)1.5%—Bryce Hamrick Janrain Capture27/6/201216/6/2026
The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks.
ModificadaMedia (5.8)2.3%—Bryce Hamrick Janrain Capture27/6/201216/6/2026
Open redirect vulnerability in the Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when synchronizing user data, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
ModificadaMedia (4.3)1.5%💥 ExploitLeadcapturepagesystem Lead Capture Page System29/1/201216/6/2026
Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter.
ModificadaMedia (5)1.4%—IBM Datacap Taskmaster Capture16/5/201116/6/2026
The eDocument Conversion Actions implementation in IBM Datacap Taskmaster Capture 8.0.1 FP1 and earlier allows remote attackers to cause a denial of service (batch abort) via a long subject line in an e-mail message that is represented in a .eml file.
ModificadaMedia (6.8)1.2%—IBM Datacap Taskmaster Capture16/5/201116/6/2026
IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an incorrect password in conjunction with an account name from a different domain.
ModificadaMedia (5)0.89%—IBM Datacap Taskmaster Capture16/5/201116/6/2026
The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vectors.
ModificadaAlta (7.5)1.1%—IBM Datacap Taskmaster Capture16/5/201116/6/2026
SQL injection vulnerability in TMWeb in IBM Datacap Taskmaster Capture 8.0.1 before FP1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5)1.5%—Phpspot PHP & CSS BBSPhpspot PHP BBSPhpspot PHP BBS CEPhpspot PHP Image Capture BBS+222/9/200916/6/2026
Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)1.0%—Phpspot PHP & CSS BBSPhpspot PHP BBSPhpspot PHP BBS CEPhpspot PHP Image Capture BBS+222/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to cookies.
ModificadaMedia (5)2.5%💥 ExploitEeye Digital Security IrisSpynet Capturenet20/10/200016/6/2026
eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.
Orbitaley — Vulnerabilidades