Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename in the list of testdrive modified files.
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename for a custom RPM.
ModificadaMedia (4.3)1.2%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.
ModificadaMedia (4.3)1.2%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing.
ModificadaAlta (9.3)1.4%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to have an unknown impact via a crafted directory pathname that is inserted into config.sh.
ModificadaAlta (7.5)1.2%💥 ExploitMarcusg MG User Fotoalbum Panel27/4/201116/6/2026
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter.
ModificadaAlta (9.3)5.1%—March-hare CVS SuiteMarch-hare Cvsnt15/9/201016/6/2026
perms.cpp in March Hare Software CVSNT 2.0.58, 2.5.01, 2.5.02, 2.5.03 before build 3736, 2.5.04 before build 2862; CVS Suite 2.5.03, 2008 before build 3736, and 2009 before 3729 allows remote attackers to bypass the permissions check, modify arbitrary modules and directories within CVSROOT, and execute arbitrary code…
ModificadaAlta (7.5)1.5%—Marcus Krause T3sec Saltedpw19/3/201016/6/2026
The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.
ModificadaMedia (4.3)1.5%💥 ExploitMarc-andre Lanciault Smartmedia20/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter.
ModificadaMedia (6.5)2.0%💥 ExploitMarcin Manek D.net CMS1/10/200916/6/2026
Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the type parameter.
ModificadaMedia (6.5)0.84%💥 ExploitMarcin Manek D.net CMS1/10/200916/6/2026
Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php.
ModificadaMedia (6.5)4.8%💥 ExploitInfireal Mxcamarchive12/8/200916/6/2026
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party…
ModificadaAlta (7.5)6.4%💥 ExploitInfireal Mxcamarchive12/8/200916/6/2026
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.
ModificadaAlta (7.5)1.4%—Marc Ingram Services6/8/200916/6/2026
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request.
ModificadaMedia (6.5)1.1%—Marc Ingram Services6/8/200916/6/2026
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges.
ModificadaAlta (7.5)1.4%—Marc Ingram Services6/8/200916/6/2026
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges.
ModificadaMedia (6.8)3.4%💥 ExploitMarcelo Costa Fileserver20/7/200916/6/2026
Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.
ModificadaAlta (7.5)2.6%💥 ExploitMarc Melvin A+ PHP Scripts News Management System8/4/200916/6/2026
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.
ModificadaMedia (6.9)0.34%—Marc Gloor Screenie8/12/200816/6/2026
screenie in screenie 1.30.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.screenie.##### temporary file.
ModificadaMedia (6.9)0.40%—Marco D'itri Ppp-udeb8/12/200816/6/2026
ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/resolv.conf.tmp temporary file.
ModificadaMedia (6.9)0.38%—Marco D'itri PPP8/12/200816/6/2026
The postinst script in ppp 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/probe-finished or (2) /tmp/ppp-errors temporary file.
ModificadaMedia (4.3)1.5%💥 ExploitMarcello Brandao Yogurt Social Network Module13/8/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5) index.php, or (6) tribes.php; or (7) the description…
ModificadaMedia (6.8)1.1%💥 ExploitMarcioforum Mforum16/7/200816/6/2026
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action.
ModificadaAlta (10)13%💥 ExploitMarch Networks 3204 DVR4/1/200816/6/2026
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.
ModificadaAlta (7.8)1.7%—Michal Marcinkowski Soldat Dedicated ServerMichal Marcinkowski Soldat Game Server25/8/200716/6/2026
Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a denial of service (client lockout) via a series of UDP join packets from a spoofed IP address, which triggers temporary blacklisting of this IP address.
Orbitaley — Vulnerabilidades