Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.23% | — | Chip Salzenberg Deliver | 26/3/2010 | 16/6/2026 | Chip Salzenberg Deliver does not properly associate a lockfile with the user who created the file, which allows local users to cause a denial of service (blockage of incoming e-mail) by creating lockfiles for arbitrary mailboxes. | |
| Modificada | Media (6.9) | 0.38% | — | Chip Salzenberg Deliver | 26/3/2010 | 16/6/2026 | Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file. | |
| Modificada | Alta (7.2) | 0.43% | — | Intel Gm45 ChipsetIntel Pm45 Express ChipsetIntel Q35 ChipsetIntel Q43 Express Chipset+1 | 24/12/2009 | 16/6/2026 | Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER… | |
| Modificada | Media (5.5) | 1.1% | — | Netgear Wndap330 FirmwareAtheros Ar9160-bc1a Chipset | 12/11/2009 | 16/6/2026 | The Atheros wireless driver, as used in Netgear WNDAP330 Wi-Fi access point with firmware 2.1.11 and other versions before 3.0.3 on the Atheros AR9160-BC1A chipset, and other products, allows remote authenticated users to cause a denial of service (device reboot or hang) and possibly execute arbitrary code via a… | |
| Modificada | Media (6.8) | 1.9% | — | Marvell 88w8361p-bem ChipsetLinksys Wap4400n | 12/11/2009 | 16/6/2026 | Multiple buffer overflows in the Marvell wireless driver, as used in Linksys WAP4400N Wi-Fi access point with firmware 1.2.17 on the Marvell 88W8361P-BEM1 chipset, and other products, allow remote 802.11-authenticated users to cause a denial of service (wireless access point crash) and possibly execute arbitrary code… | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Chipmunk-scripts Chipmunk Topsites | 25/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Chipmunk Topsites allows remote attackers to inject arbitrary web script or HTML via the start parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Chipmunk-scripts Chipmunk Topsites | 25/8/2009 | 16/6/2026 | SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 4.9% | 💥 Exploit | Microchip Mplab IDE | 18/5/2009 | 16/6/2026 | Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Microchip Mplab IDE | 11/5/2009 | 16/6/2026 | Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and possibly other fields. | |
| Modificada | Alta (7.5) | 1.2% | — | Chipmunk Scripts Chipmunk Guestbook | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Chipmunk Guestbook 1.4m allows remote attackers to execute arbitrary SQL commands via the start parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Chipmunk Scripts Chipmunk Blogger | 3/2/2009 | 16/6/2026 | SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Chipmunk Scripts Chipmunk Blogger | 3/2/2009 | 16/6/2026 | Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions. | |
| Modificada | Alta (7.5) | 2.6% | — | Chipmunk Scripts Chipmunk CMS | 4/11/2008 | 16/6/2026 | board/admin/reguser.php in Chipmunk CMS 1.3 allows remote attackers to bypass authentication and gain administrator privileges via a direct request. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.3) | 1.8% | — | Atheros Ar5416-ac1e ChipsetLinksys Wrt350n | 5/9/2008 | 16/6/2026 | The driver for the Linksys WRT350N Wi-Fi access point with firmware 2.00.17 on the Atheros AR5416-AC1E chipset does not properly parse the Atheros vendor-specific information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly… | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Chipmunk Scripts Chipmunk Blogger | 15/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrary web script or HTML via the membername parameter to (1) members.php, (2) comments.php, (3) photos.php, (4) archive.php, or (5) cat.php. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Chipmunk Scripts Chipmunk Directory | 24/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in directory/index.php in Chipmunk directory allows remote attackers to inject arbitrary web script or HTML via the start parameter. | |
| Modificada | Baja (3.5) | 0.89% | — | Chipmunk Scripts Chipmunk Blogger | 24/2/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery. | |
| Modificada | Alta (9) | 4.5% | 💥 Exploit | Centrality Communications Pa168 Chipset | 26/1/2007 | 16/6/2026 | The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain… | |
| Modificada | Media (6) | 1.4% | — | FIX AND Chips Computer Services FIX AND Chips CMS | 9/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Fix and Chips CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) delete-announce.php; the (2) Announcement form field in (b) staff.php; the (3) Client Name, (4) Business Name, (5) Street, (6) Address 2, (7)… | |
| Modificada | Media (6.8) | 2.9% | — | Microchip Data Systems Ziptv FOR C++ BuilderMicrochip Data Systems Ziptv FOR Delphi 7Pentaware Pentasuite-proPentaware Pentazip | 8/9/2006 | 16/6/2026 | Heap-based buffer overflow in the TZipTV component in (1) ZipTV for Delphi 7 2006.1.26 and for C++ Builder 2006-1.16, (2) PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221, and possibly other products, allows user-assisted attackers to execute arbitrary code via an ARJ archive with a long header. NOTE: the ACE archive… | |
| Modificada | Media (5) | 1.4% | — | Chipmailer | 21/6/2006 | 16/6/2026 | Chipmailer 1.09 allows remote attackers to obtain sensitive information via a direct request to php.php, which displays the output of the phpinfo function. | |
| Modificada | Alta (7.5) | 1.3% | — | Chipmailer | 21/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in main.php in Chipmailer 1.09 allow remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by (1) anfang, (2) name, (3) mail, (4) anrede, (5) vorname, (6) nachname, (7) gebtag, (8) gebmonat, and (9) gebjahr. | |
| Modificada | Media (4.3) | 1.2% | — | Chipmailer | 21/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in main.php in Chipmailer 1.09 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) betreff, (3) mail, and (4) text parameters. | |
| Modificada | Media (4.3) | 1.7% | — | Chipmunk Scripts Chipmunk Guestbook | 2/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Chipmunk guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) start parameter in (a) index.php; (2) forumID parameter in index.php, (b) newtopic.php, and (c) reply.php; and (3) ID parameter to (d) edit.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Chipmunk Scripts Chipmunk Guestbook | 11/4/2006 | 16/6/2026 | SQL injection vulnerability in admin/login.php in Chipmunk Guestbook allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the User name. |