Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.1% | — | Radio Toolbox Steamcast | 1/2/2008 | 16/6/2026 | Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL dereference when malloc fails. | |
| Modificada | Alta (10) | 54% | 💥 Exploit | Radio Toolbox Steamcast | 1/2/2008 | 16/6/2026 | Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | MP3 Toolbox | 27/11/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitrary PHP code via a URL in the skin_file parameter. | |
| Modificada | Media (6.4) | 1.1% | — | Zephyrsoft Toolbox Address Book Continued | 27/2/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php. NOTE: some of these details are obtained from third… | |
| Modificada | Media (6.4) | 15% | — | Zephyrsoft Toolbox Address Book Continued | 27/2/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was… | |
| Modificada | Media (5) | 4.8% | 💥 Exploit | HP Color Laserjet 2500 ToolboxHP Color Laserjet 4600 ToolboxHP Color LaserjetHP Color Laserjet 2500+5 | 6/4/2006 | 16/6/2026 | Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225. | |
| Modificada | Alta (10) | 6.6% | — | IBM Tivoli Firewall Toolbox | 31/12/2003 | 16/6/2026 | Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors. |