Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.80% | — | Snowtide Pdfxstream | 1/10/2019 | 17/6/2026 | In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Globiz Solutions Snowfox Content Management System | 8/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of administrators for requests that add a new admin account via a submit action in the admin/accounts/create uri to snowfox/. | |
| Modificada | Media (5.8) | 2.2% | — | Globiz Solutions Snowfox Content Management System | 8/12/2014 | 17/6/2026 | Open redirect vulnerability in modules/system/controller/selectlanguage.class.php in Snowfox CMS 1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the rd parameter in a submit action to snowfox/. | |
| Modificada | Alta (10) | 61% | 💥 Exploit | Ericom Accessnow Server | 4/6/2014 | 17/6/2026 | Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a request for a non-existent file. | |
| Modificada | Media (6.9) | 0.40% | — | Snowfoxsoft Snowfox Total Video Converter | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in SnowFox Total Video Converter 2.5.1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .avi file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Snowhall Silurus System | 25/8/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory.php, and the (3) keywords parameter to search.php. | |
| Modificada | Media (4.3) | 1.1% | — | Phpscriptsnow Real Time Currency Exchange | 15/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in rates.php in Real Time Currency Exchange allows remote attackers to inject arbitrary web script or HTML via the Amount parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpscriptsnow Astrology | 10/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in celebrities.php in PHP Scripts Now Astrology allows remote attackers to inject arbitrary web script or HTML via the day parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Snowflake T3blog | 2/3/2010 | 16/6/2026 | SQL injection vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Snowflake T3blog | 2/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Snowhall Silurus System | 9/9/2009 | 16/6/2026 | SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Snowhall Silurus System | 4/9/2009 | 16/6/2026 | SQL injection vulnerability in wcategory.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Phpscriptsnow Riddles | 20/8/2009 | 16/6/2026 | SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | Phpscriptsnow Riddles | 20/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpscriptsnow Hangman | 20/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Phpscriptsnow Hangman | 20/8/2009 | 16/6/2026 | SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Phpscriptsnow President Bios | 20/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Phpscriptsnow President Bios | 20/8/2009 | 16/6/2026 | SQL injection vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to execute arbitrary SQL commands via the rank parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Phpscriptsnow World's Tallest Buildings | 20/8/2009 | 16/6/2026 | SQL injection vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to execute arbitrary SQL commands via the rank parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpscriptsnow World's Tallest Buildings | 20/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter. | |
| Modificada | Media (6.4) | 5.9% | 💥 Exploit | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow. | |
| Modificada | Media (6.4) | 2.2% | — | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request. | |
| Modificada | Media (6.4) | 7.4% | 💥 Exploit | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request. |