Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 3.2% | — | AmavisAvast AntivirusAvast Antivirus HomeAvast Antivirus Professional+9 | 9/5/2007 | 16/6/2026 | unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. | |
| Modificada | Alta (9.3) | 76% | — | Microsoft Biztalk ServerMicrosoft Capicom | 8/5/2007 | 16/6/2026 | Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability." | |
| Modificada | Media (6.8) | 1.3% | — | Picozip | 18/4/2007 | 16/6/2026 | Directory traversal vulnerability in Acubix PicoZip 4.02 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the file path in an (1) GZ, (2) TAR, (3) RAR, (4) JAR, or (5) ZIP archive. | |
| Modificada | Alta (7.5) | 9.0% | 💥 Exploit | Picozip | 16/6/2006 | 16/6/2026 | Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP archive, which is triggered when the user moves the mouse over the archive. | |
| Modificada | Alta (7.5) | 2.4% | — | Pico Server | 16/6/2005 | 16/6/2026 | Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequence in the URL, which results in an incorrect directory depth count. | |
| Modificada | Alta (7.5) | 3.2% | — | Pico Server | 11/6/2005 | 16/6/2026 | Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request. | |
| Modificada | Alta (7.5) | 3.8% | — | Newmad Technologies Picowebserver | 1/6/2005 | 16/6/2026 | Stack-based buffer overflow in PicoWebServer 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URL. | |
| Modificada | Alta (7.5) | 2.0% | — | Pico Server PservAI | 17/5/2005 | 16/6/2026 | Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Pico Server | 16/5/2005 | 16/6/2026 | Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL. | |
| Modificada | Alta (7.5) | 1.2% | — | Pico Server | 16/5/2005 | 16/6/2026 | Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Pico Server | 16/5/2005 | 16/6/2026 | Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Picophone Internet Telephone | 24/3/2004 | 16/6/2026 | Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Pico Server | 31/12/2002 | 16/6/2026 | Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byte TCP stream message, which triggers an off-by-one buffer overflow, or (2) a long method name in an HTTP request, (3) a long version number… |