Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | Amazing Flash Commerce Afcommerce Shopping Cart | 24/7/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Amazing Flash AFCommerce Shopping Cart permite a atacantes remotos inyectar scripts web o HTML de su elección mediante la caja de texto "nueva revisión". | |
| Modificada | Media (5.1) | 8.4% | — | Adobe Flash Player | 13/7/2006 | 16/6/2026 | Vulnerabilidad no especificada en Adobe (Macromedia) Flash Player 8.0.24.0 permite a atacantes remotos ejecutar comandos de su elección mediante un archivo .swf mal formado que resulta en "múltiples errores de acceso inapropiado a memoria". | |
| Modificada | Baja (2.6) | 7.6% | — | Adobe Flash Player | 13/7/2006 | 16/6/2026 | Vulnerabilidad no especificada en Adobe (Macromedia) Flash Player 8.0.24.0 permite a atacantes remotos provocar una denegación de servicio (caída del navegador) mediante un fichero .swf comprimido mal formado, un asunto diferente de CVE-2006-3587. | |
| Modificada | Media (4.3) | 1.3% | — | Sloughflash Sf-users | 4/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element. | |
| Modificada | Media (5.1) | 6.8% | — | Macromedia Flash Player | 15/3/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Topcmm Computing 123 Flash Chat Server | 25/1/2006 | 16/6/2026 | Vulnerabilidad de inyección de Eval en 123 Flash Chat Server 5.0 y 5.1 permite a atacantes ejecutar código mediante un "username" artesanal. | |
| Modificada | Media (5) | 1.6% | — | Topcmm Computing 123 Flash Chat Server | 16/1/2006 | 16/6/2026 | Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field. | |
| Modificada | Alta (7.2) | 1.2% | — | Adobe CaptivateAdobe ContributeAdobe DirectorAdobe Dreamweaver+5 | 31/12/2005 | 16/6/2026 | Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System. | |
| Modificada | Alta (7.8) | 4.2% | 💥 Exploit | Macromedia Flash Media Server | 14/12/2005 | 16/6/2026 | El Servicio de Administración (FMSAdmin.exe) en Macromedia Flash Media Server 2.0 r1145 permite a atacantes remotos causar una denegación de servicio (caída de aplicación) mediante una petición mal formada con un sólo carácter al puerto 1111. | |
| Modificada | Alta (7.8) | 1.5% | — | Macromedia Flash Communication Server | 29/11/2005 | 16/6/2026 | Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |
| Modificada | Alta (7.8) | 1.7% | — | Macromedia Breeze Communication ServerAIMacromedia Breeze Live ServerAIMacromedia Flash PlayerAI | 29/11/2005 | 16/6/2026 | Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Macromedia Flash Player | 16/11/2005 | 16/6/2026 | Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper… | |
| Modificada | Media (5.1) | 6.8% | — | Macromedia Flash Player | 5/11/2005 | 16/6/2026 | Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer. | |
| Modificada | Baja (2.1) | 0.35% | — | Toshiba Acpi Flash Bios | 2/5/2005 | 16/6/2026 | An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed. NOTE: it has been debated as to whether or not this issue poses a security vulnerability,… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Net2soft Flash FTP ServerAI | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot). | |
| Modificada | Baja (2.1) | 0.78% | — | Jera Technology Flash Messaging Server | 31/12/2004 | 16/6/2026 | Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Jera Technology Flash Messaging | 31/12/2004 | 16/6/2026 | Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Macromedia DirectorMacromedia Flash Player | 5/1/2004 | 16/6/2026 | El Reproductor de Macromedia Flash en versiones anteriores a 7,0,19,0 almacena un fichero de datos de Flash en una localización predecible, accesible a navegadores web como Internet Explorer y Opera, lo que permite a a atacantes remotos leer ficheros restringidos mediante vulnerabilidades en navegadores web cuya… | |
| Modificada | Media (6.4) | 0.69% | — | Flashfxp | 31/12/2003 | 16/6/2026 | FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access. | |
| Modificada | Media (4.3) | 1.4% | — | Macromedia Flash | 5/5/2003 | 16/6/2026 | Vulnerabilidad de scripting cruza-sitios (XSS) en la capacidad de seguimiento de publicidad de usuario Macromedia Flash permite a atacantes remotos insertar Javascript arbitrario mediante el campo clickTAG. | |
| Modificada | Media (5) | 1.9% | — | Macromedia Flash PlayerMacromedia Shockwave | 22/4/2003 | 16/6/2026 | Macromedia Flash Plugin anteriores a 6.0.47 permite a atacantes remotos saltarse las restricciones de mismo dominio y leer ficheros arbitrarios mediante Una redirección HTTP Una base "file://" en un documento web una URL relativa de una archivo web (fichero.mht) | |
| Modificada | Media (5) | 2.3% | — | Macromedia Flash Player | 31/3/2003 | 16/6/2026 | Macromedia Flash Player permite a atacantes remotos la lectura arbitraria de ficheros mediante una rutina XML en un fichero .swf albergado en una SMB compartida en remoto. | |
| Modificada | Media (5) | 2.0% | — | Macromedia Flash Player | 31/12/2002 | 16/6/2026 | Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of service (bandwidth, resource, and CPU consumption) via the (1) loadMovie or (2) loadSound commands, which continue to execute until the browser is closed. | |
| Modificada | Baja (2.1) | 0.35% | — | Flashfxp | 31/12/2002 | 16/6/2026 | FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of other users by editing the queue properties. | |
| Modificada | Media (5) | 1.7% | — | Macromedia Flash Player | 31/12/2002 | 16/6/2026 | Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a Flash Shockwave (.SWF) file, as demonstrated by by ROT13 encoding the body of the file but not the headers. |