Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.32% | — | Trianglemicroworks Ansi C Source Code LibrariesTrianglemicroworks .net Communication Protocol ComponentsTrianglemicroworks Scada Data Gateway | 9/9/2013 | 16/6/2026 | Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line. | |
| Modificada | Alta (7.8) | 1.5% | — | Trianglemicroworks .net Communication Protocol ComponentsTrianglemicroworks Ansi C Source Code LibrariesTrianglemicroworks Scada Data Gateway | 9/9/2013 | 16/6/2026 | Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet. | |
| Modificada | Baja (3.5) | 0.83% | — | Cutesoft Components Cute Editor | 21/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in InsertDocument.aspx in CuteSoft Cute Editor 6.4 allows remote authenticated users to inject arbitrary web script or HTML via the _UploadID parameter. | |
| Analizada | Alta (8.8) | 72% | ⚠ Explotación activa | Microsoft Commerce ServerMicrosoft Host Integration ServerMicrosoft OfficeMicrosoft Office WEB Components+3 | 15/8/2012 | 16/6/2026 | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2,… | |
| Modificada | Crítica (9.8) | 29% | — | Microsoft Data Access ComponentsMicrosoft Windows Data Access Components | 10/7/2012 | 16/6/2026 | Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability." | |
| Modificada | Media (5) | 2.2% | — | Invensys DasabcipInvensys Daserver Runtime ComponentsInvensys DassidirectInvensys Intouch/wonderware Application Server+1 | 5/7/2012 | 16/6/2026 | Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and… | |
| Modificada | Alta (7.5) | 8.0% | — | Icu-project International Components FOR Unicode | 21/6/2012 | 16/6/2026 | Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization. | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft OfficeMicrosoft Office WEB ComponentsMicrosoft SQL Server 2000Microsoft SQL Server 2005+6 | 10/4/2012 | 16/6/2026 | The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce… | |
| Modificada | Alta (9.3) | 54% | 💥 Exploit | Microsoft Data Access ComponentsMicrosoft Windows Data Access Components | 12/1/2011 | 16/6/2026 | Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer… | |
| Modificada | Alta (9.3) | 34% | — | Microsoft Data Access ComponentsMicrosoft Windows Data Access Components | 12/1/2011 | 16/6/2026 | Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument,… | |
| Modificada | Media (5) | 6.7% | 💥 Exploit | Cutesoft Components Cute Editor FOR Asp.net | 5/3/2010 | 16/6/2026 | Directory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Componentslab COM Sqlreport | 27/2/2010 | 16/6/2026 | SQL injection vulnerability in the SQL Reports (com_sqlreport) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter to ajax/print.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 29% | — | Microsoft Biztalk ServerMicrosoft Internet Security AND Acceleration ServerMicrosoft OfficeMicrosoft Office WEB Components+1 | 12/8/2009 | 16/6/2026 | Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1,… | |
| Modificada | Alta (9.3) | 52% | 💥 Exploit | Microsoft ISA ServerMicrosoft OfficeMicrosoft Office WEB Components | 12/8/2009 | 16/6/2026 | Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer… | |
| Modificada | Alta (9.3) | 26% | — | Microsoft ISA ServerMicrosoft OfficeMicrosoft Office WEB Components | 12/8/2009 | 16/6/2026 | The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business… | |
| Modificada | Alta (9.3) | 62% | 💥 Exploit | Microsoft ISA ServerMicrosoft OfficeMicrosoft Office WEB ComponentsMicrosoft Office XP | 15/7/2009 | 16/6/2026 | The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Vclcomponents Yappa-ng | 24/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Fritz Berger yet another php photo album - next generation (yappa-ng) allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI. | |
| Modificada | Alta (10) | 1.5% | — | Midgard Components Framework | 21/10/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Midgard Components (MidCOM) Framework before 8.09.1 have unknown impact and attack vectors. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Vclcomponents Relative Real Estate Systems | 15/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action. | |
| Modificada | Alta (9.3) | 2.5% | — | Icu-project International Components FOR Unicode | 29/1/2008 | 16/6/2026 | Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large… | |
| Modificada | Media (6.8) | 2.9% | — | Icu-project International Components FOR Unicode | 29/1/2008 | 16/6/2026 | libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames. | |
| Modificada | Alta (9.3) | 7.0% | 💥 Exploit | Clever Components Internet Activex Suite | 30/7/2007 | 16/6/2026 | Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the GetToFile method. NOTE: some of these details are obtained from… | |
| Modificada | Alta (9.3) | 7.0% | 💥 Exploit | Clever Components Clever Database Comparer | 14/5/2007 | 16/6/2026 | Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via a long argument to the ConnectToDatabase function. | |
| Modificada | Alta (10) | 6.2% | 💥 Exploit | Telestream Flip4mac Windows Media Components FOR Quicktime | 31/1/2007 | 16/6/2026 | Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption. | |
| Modificada | Alta (9.3) | 40% | — | Microsoft Office WEB Components | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability." |