Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

138 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.23%—Chip Salzenberg Deliver26/3/201016/6/2026
Chip Salzenberg Deliver does not properly associate a lockfile with the user who created the file, which allows local users to cause a denial of service (blockage of incoming e-mail) by creating lockfiles for arbitrary mailboxes.
ModificadaMedia (6.9)0.38%—Chip Salzenberg Deliver26/3/201016/6/2026
Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file.
ModificadaAlta (7.2)0.43%—Intel Gm45 ChipsetIntel Pm45 Express ChipsetIntel Q35 ChipsetIntel Q43 Express Chipset+124/12/200916/6/2026
Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER…
ModificadaMedia (5.5)1.1%—Netgear Wndap330 FirmwareAtheros Ar9160-bc1a Chipset12/11/200916/6/2026
The Atheros wireless driver, as used in Netgear WNDAP330 Wi-Fi access point with firmware 2.1.11 and other versions before 3.0.3 on the Atheros AR9160-BC1A chipset, and other products, allows remote authenticated users to cause a denial of service (device reboot or hang) and possibly execute arbitrary code via a…
ModificadaMedia (6.8)1.9%—Marvell 88w8361p-bem ChipsetLinksys Wap4400n12/11/200916/6/2026
Multiple buffer overflows in the Marvell wireless driver, as used in Linksys WAP4400N Wi-Fi access point with firmware 1.2.17 on the Marvell 88W8361P-BEM1 chipset, and other products, allow remote 802.11-authenticated users to cause a denial of service (wireless access point crash) and possibly execute arbitrary code…
ModificadaMedia (4.3)1.4%💥 ExploitChipmunk-scripts Chipmunk Topsites25/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Chipmunk Topsites allows remote attackers to inject arbitrary web script or HTML via the start parameter.
ModificadaAlta (7.5)0.97%💥 ExploitChipmunk-scripts Chipmunk Topsites25/8/200916/6/2026
SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)4.9%💥 ExploitMicrochip Mplab IDE18/5/200916/6/2026
Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608.
ModificadaAlta (9.3)11%💥 ExploitMicrochip Mplab IDE11/5/200916/6/2026
Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and possibly other fields.
ModificadaAlta (7.5)1.2%—Chipmunk Scripts Chipmunk Guestbook2/3/200916/6/2026
SQL injection vulnerability in index.php in Chipmunk Guestbook 1.4m allows remote attackers to execute arbitrary SQL commands via the start parameter.
ModificadaAlta (7.5)1.1%💥 ExploitChipmunk Scripts Chipmunk Blogger3/2/200916/6/2026
SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaAlta (7.5)2.3%💥 ExploitChipmunk Scripts Chipmunk Blogger3/2/200916/6/2026
Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions.
ModificadaAlta (7.5)2.6%—Chipmunk Scripts Chipmunk CMS4/11/200816/6/2026
board/admin/reguser.php in Chipmunk CMS 1.3 allows remote attackers to bypass authentication and gain administrator privileges via a direct request. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.3)1.8%—Atheros Ar5416-ac1e ChipsetLinksys Wrt350n5/9/200816/6/2026
The driver for the Linksys WRT350N Wi-Fi access point with firmware 2.00.17 on the Atheros AR5416-AC1E chipset does not properly parse the Atheros vendor-specific information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly…
ModificadaMedia (4.3)1.2%💥 ExploitChipmunk Scripts Chipmunk Blogger15/7/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrary web script or HTML via the membername parameter to (1) members.php, (2) comments.php, (3) photos.php, (4) archive.php, or (5) cat.php. NOTE: the provenance of this information is unknown; the…
ModificadaMedia (6.8)1.8%💥 ExploitChipmunk Scripts Chipmunk Directory24/2/200716/6/2026
Cross-site scripting (XSS) vulnerability in directory/index.php in Chipmunk directory allows remote attackers to inject arbitrary web script or HTML via the start parameter.
ModificadaBaja (3.5)0.89%—Chipmunk Scripts Chipmunk Blogger24/2/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery.
ModificadaAlta (9)4.5%💥 ExploitCentrality Communications Pa168 Chipset26/1/200716/6/2026
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain…
ModificadaMedia (6)1.4%—FIX AND Chips Computer Services FIX AND Chips CMS9/1/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Fix and Chips CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) delete-announce.php; the (2) Announcement form field in (b) staff.php; the (3) Client Name, (4) Business Name, (5) Street, (6) Address 2, (7)…
ModificadaMedia (6.8)2.9%—Microchip Data Systems Ziptv FOR C++ BuilderMicrochip Data Systems Ziptv FOR Delphi 7Pentaware Pentasuite-proPentaware Pentazip8/9/200616/6/2026
Heap-based buffer overflow in the TZipTV component in (1) ZipTV for Delphi 7 2006.1.26 and for C++ Builder 2006-1.16, (2) PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221, and possibly other products, allows user-assisted attackers to execute arbitrary code via an ARJ archive with a long header. NOTE: the ACE archive…
ModificadaMedia (5)1.4%—Chipmailer21/6/200616/6/2026
Chipmailer 1.09 allows remote attackers to obtain sensitive information via a direct request to php.php, which displays the output of the phpinfo function.
ModificadaAlta (7.5)1.3%—Chipmailer21/6/200616/6/2026
Multiple SQL injection vulnerabilities in main.php in Chipmailer 1.09 allow remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by (1) anfang, (2) name, (3) mail, (4) anrede, (5) vorname, (6) nachname, (7) gebtag, (8) gebmonat, and (9) gebjahr.
ModificadaMedia (4.3)1.2%—Chipmailer21/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in main.php in Chipmailer 1.09 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) betreff, (3) mail, and (4) text parameters.
ModificadaMedia (4.3)1.7%—Chipmunk Scripts Chipmunk Guestbook2/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in Chipmunk guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) start parameter in (a) index.php; (2) forumID parameter in index.php, (b) newtopic.php, and (c) reply.php; and (3) ID parameter to (d) edit.php.
ModificadaAlta (7.5)1.2%💥 ExploitChipmunk Scripts Chipmunk Guestbook11/4/200616/6/2026
SQL injection vulnerability in admin/login.php in Chipmunk Guestbook allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the User name.
Orbitaley — Vulnerabilidades