Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 5 respecto a la semana anterior
Críticas / altas1274▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
–

1268 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%💥 ExploitLifetype13/7/200616/6/2026
Vulnerabilidad de inyección SQL en index.php en LifeType 1.0.5 permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro Date en una operación Default.
ModificadaAlta (7.5)1.3%💥 ExploitSoftnews Media Group Datalife Engine24/6/200616/6/2026
Vulnerabilidad de inyección SQL en index.php en DataLife Engine v4.1 y anteriores permite a atacantes remotos ejecutar comandos SQL a través de valores de doble codificación en el parámetro user en una acción userinfo.
ModificadaAlta (7.5)1.4%💥 ExploitLifetype6/6/200616/6/2026
SQL injection vulnerability in index.php in LifeType 1.0.4 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a ViewArticle action (viewarticleaction.class.php).
ModificadaBaja (2.6)2.0%💥 ExploitLifetype18/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Lifetype 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the show parameter in a Template operation.
ModificadaMedia (5)1.4%—Lifetype18/4/200616/6/2026
index.php in Lifetype 1.0.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which reveals the path in an error message.
ModificadaMedia (4)2.6%💥 ExploitValve Software Half-life Cstrike Dedicated Server16/2/200616/6/2026
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port 27015.
ModificadaMedia (4.3)1.7%💥 ExploitLiferay Portal Enterprise20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters.
ModificadaAlta (7.5)1.2%—Newlife Blogger1/6/200516/6/2026
Multiple SQL injection vulnerabilities in NewLife Blogger before 3.3.1 allow remote attackers to execute arbitrary SQL commands via unknown attack vectors.
ModificadaMedia (5)1.6%—Valve Software Half-lifeValve Software Half-life Dedicated Server27/7/200416/6/2026
El motor de Half-Life antes del 7 de julio de 2004 permite a atacantes remotos causar una denegación de servicio (caída del cliente o el servidor) mediante un paquete fragmentado vació.
ModificadaMedia (4.3)2.1%💥 ExploitLiferay Enterprise Portal22/5/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.
ModificadaAlta (7.2)0.48%—Calife15/3/200416/6/2026
Desbordamiento de búfer basado en el montón en Calife 2.8.5 y anteriores puede permitir a usuarios locales ejecutar código arbitrario mediante una contraseña larga.
ModificadaMedia (5.2)2.6%💥 ExploitValve Software Half-life Cstrike Dedicated Server31/12/200316/6/2026
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents "absence of player informations," a related…
ModificadaMedia (5)3.2%💥 ExploitValve Software Half-lifeValve Software Half-life Dedicated Server4/10/200216/6/2026
Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial challenge with different cd_key values, which reaches the player limit and prevents other players from connecting until the original responses have timed out.
ModificadaAlta (7.5)2.1%—Valve Software Half-life20/9/200116/6/2026
Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows malicious remote servers to execute arbitrary code via a long console command.
ModificadaAlta (7.5)3.2%—Sierra Half-lifeValve Software Half-life27/6/200116/6/2026
Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.
ModificadaAlta (7.5)2.3%—Sierra Half-lifeValve Software Half-life Dedicated Server27/6/200116/6/2026
Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.
ModificadaAlta (10)3.8%—Valve Software Half-life Dedicated Server19/12/200023/9/2026
Desbordamiento de búfer en el servidor dedicado de Half Life anterior a la compilación 3104 permite a atacantes remotos ejecutar comandos arbitrarios a través de un comando rcon largo.
ModificadaAlta (10)3.5%—Valve Software Half-life Dedicated Server19/12/200023/9/2026
Vulnerabilidad de cadena de formato en el servidor dedicado de Half Life build 3104 y anteriores permite a atacantes remotos ejecutar comandos arbitrarios inyectando cadenas de formato en el comando changelevel, a través de la consola del sistema o rcon.