Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1334 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.4%—Amazing Flash Commerce Afcommerce Shopping Cart24/7/200616/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Amazing Flash AFCommerce Shopping Cart permite a atacantes remotos inyectar scripts web o HTML de su elección mediante la caja de texto "nueva revisión".
ModificadaMedia (5.1)8.4%—Adobe Flash Player13/7/200616/6/2026
Vulnerabilidad no especificada en Adobe (Macromedia) Flash Player 8.0.24.0 permite a atacantes remotos ejecutar comandos de su elección mediante un archivo .swf mal formado que resulta en "múltiples errores de acceso inapropiado a memoria".
ModificadaBaja (2.6)7.6%—Adobe Flash Player13/7/200616/6/2026
Vulnerabilidad no especificada en Adobe (Macromedia) Flash Player 8.0.24.0 permite a atacantes remotos provocar una denegación de servicio (caída del navegador) mediante un fichero .swf comprimido mal formado, un asunto diferente de CVE-2006-3587.
ModificadaMedia (4.3)1.3%—Sloughflash Sf-users4/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element.
ModificadaMedia (5.1)6.8%—Macromedia Flash Player15/3/200616/6/2026
Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.
ModificadaAlta (7.5)3.7%💥 ExploitTopcmm Computing 123 Flash Chat Server25/1/200616/6/2026
Vulnerabilidad de inyección de Eval en 123 Flash Chat Server 5.0 y 5.1 permite a atacantes ejecutar código mediante un "username" artesanal.
ModificadaMedia (5)1.6%—Topcmm Computing 123 Flash Chat Server16/1/200616/6/2026
Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field.
ModificadaAlta (7.2)1.2%—Adobe CaptivateAdobe ContributeAdobe DirectorAdobe Dreamweaver+531/12/200516/6/2026
Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.
ModificadaAlta (7.8)4.2%💥 ExploitMacromedia Flash Media Server14/12/200516/6/2026
El Servicio de Administración (FMSAdmin.exe) en Macromedia Flash Media Server 2.0 r1145 permite a atacantes remotos causar una denegación de servicio (caída de aplicación) mediante una petición mal formada con un sólo carácter al puerto 1111.
ModificadaAlta (7.8)1.5%—Macromedia Flash Communication Server29/11/200516/6/2026
Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133).
ModificadaAlta (7.8)1.7%—Macromedia Breeze Communication ServerAIMacromedia Breeze Live ServerAIMacromedia Flash PlayerAI29/11/200516/6/2026
Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133).
ModificadaAlta (7.5)10%💥 ExploitMacromedia Flash Player16/11/200516/6/2026
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper…
ModificadaMedia (5.1)6.8%—Macromedia Flash Player5/11/200516/6/2026
Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.
ModificadaBaja (2.1)0.35%—Toshiba Acpi Flash Bios2/5/200516/6/2026
An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed. NOTE: it has been debated as to whether or not this issue poses a security vulnerability,…
ModificadaAlta (7.5)2.8%💥 ExploitNet2soft Flash FTP ServerAI31/12/200416/6/2026
Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).
ModificadaBaja (2.1)0.78%—Jera Technology Flash Messaging Server31/12/200416/6/2026
Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected.
ModificadaMedia (5)3.1%💥 ExploitJera Technology Flash Messaging31/12/200416/6/2026
Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters.
ModificadaMedia (5)3.0%💥 ExploitMacromedia DirectorMacromedia Flash Player5/1/200416/6/2026
El Reproductor de Macromedia Flash en versiones anteriores a 7,0,19,0 almacena un fichero de datos de Flash en una localización predecible, accesible a navegadores web como Internet Explorer y Opera, lo que permite a a atacantes remotos leer ficheros restringidos mediante vulnerabilidades en navegadores web cuya…
ModificadaMedia (6.4)0.69%—Flashfxp31/12/200316/6/2026
FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.
ModificadaMedia (4.3)1.4%—Macromedia Flash5/5/200316/6/2026
Vulnerabilidad de scripting cruza-sitios (XSS) en la capacidad de seguimiento de publicidad de usuario Macromedia Flash permite a atacantes remotos insertar Javascript arbitrario mediante el campo clickTAG.
ModificadaMedia (5)1.9%—Macromedia Flash PlayerMacromedia Shockwave22/4/200316/6/2026
Macromedia Flash Plugin anteriores a 6.0.47 permite a atacantes remotos saltarse las restricciones de mismo dominio y leer ficheros arbitrarios mediante Una redirección HTTP Una base "file://" en un documento web una URL relativa de una archivo web (fichero.mht)
ModificadaMedia (5)2.3%—Macromedia Flash Player31/3/200316/6/2026
Macromedia Flash Player permite a atacantes remotos la lectura arbitraria de ficheros mediante una rutina XML en un fichero .swf albergado en una SMB compartida en remoto.
ModificadaMedia (5)2.0%—Macromedia Flash Player31/12/200216/6/2026
Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of service (bandwidth, resource, and CPU consumption) via the (1) loadMovie or (2) loadSound commands, which continue to execute until the browser is closed.
ModificadaBaja (2.1)0.35%—Flashfxp31/12/200216/6/2026
FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of other users by editing the queue properties.
ModificadaMedia (5)1.7%—Macromedia Flash Player31/12/200216/6/2026
Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a Flash Shockwave (.SWF) file, as demonstrated by by ROT13 encoding the body of the file but not the headers.