Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.80%—Snowtide Pdfxstream1/10/201917/6/2026
In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.
ModificadaMedia (6.8)2.3%💥 ExploitGlobiz Solutions Snowfox Content Management System8/12/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of administrators for requests that add a new admin account via a submit action in the admin/accounts/create uri to snowfox/.
ModificadaMedia (5.8)2.2%—Globiz Solutions Snowfox Content Management System8/12/201417/6/2026
Open redirect vulnerability in modules/system/controller/selectlanguage.class.php in Snowfox CMS 1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the rd parameter in a submit action to snowfox/.
ModificadaAlta (10)61%💥 ExploitEricom Accessnow Server4/6/201417/6/2026
Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a request for a non-existent file.
ModificadaMedia (6.9)0.40%—Snowfoxsoft Snowfox Total Video Converter7/9/201216/6/2026
Untrusted search path vulnerability in SnowFox Total Video Converter 2.5.1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .avi file. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.3%💥 ExploitSnowhall Silurus System25/8/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory.php, and the (3) keywords parameter to search.php.
ModificadaMedia (4.3)1.1%—Phpscriptsnow Real Time Currency Exchange15/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in rates.php in Real Time Currency Exchange allows remote attackers to inject arbitrary web script or HTML via the Amount parameter.
ModificadaMedia (4.3)1.5%💥 ExploitPhpscriptsnow Astrology10/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in celebrities.php in PHP Scripts Now Astrology allows remote attackers to inject arbitrary web script or HTML via the day parameter.
ModificadaAlta (7.5)1.1%—Snowflake T3blog2/3/201016/6/2026
SQL injection vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.0%—Snowflake T3blog2/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.0%💥 ExploitSnowhall Silurus System9/9/200916/6/2026
SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (7.5)1.0%💥 ExploitSnowhall Silurus System4/9/200916/6/2026
SQL injection vulnerability in wcategory.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.99%💥 ExploitPhpscriptsnow Riddles20/8/200916/6/2026
SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaMedia (4.3)3.1%💥 ExploitPhpscriptsnow Riddles20/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter.
ModificadaMedia (4.3)1.5%💥 ExploitPhpscriptsnow Hangman20/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter.
ModificadaAlta (7.5)0.99%💥 ExploitPhpscriptsnow Hangman20/8/200916/6/2026
SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter.
ModificadaMedia (4.3)1.1%—Phpscriptsnow President Bios20/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter.
ModificadaAlta (7.5)1.2%—Phpscriptsnow President Bios20/8/200916/6/2026
SQL injection vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to execute arbitrary SQL commands via the rank parameter.
ModificadaAlta (7.5)0.99%💥 ExploitPhpscriptsnow World's Tallest Buildings20/8/200916/6/2026
SQL injection vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to execute arbitrary SQL commands via the rank parameter.
ModificadaMedia (4.3)1.5%💥 ExploitPhpscriptsnow World's Tallest Buildings20/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter.
ModificadaMedia (6.4)5.9%💥 ExploitSnowblind.net Snowblind WEB Server16/6/200316/6/2026
Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence.
ModificadaAlta (7.5)3.5%💥 ExploitSnowblind.net Snowblind WEB Server16/6/200316/6/2026
Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.
ModificadaMedia (6.4)2.2%—Snowblind.net Snowblind WEB Server16/6/200316/6/2026
Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request.
ModificadaMedia (6.4)7.4%💥 ExploitSnowblind.net Snowblind WEB Server16/6/200316/6/2026
Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.
Orbitaley — Vulnerabilidades