Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2767▼ 5 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 207 respecto a la semana anterior
1419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Superfreaker Studios Upublisher | 8/12/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en Superfreaker Studios UPublisher 1.0 permite a atacantes remotos ejecutar comandos SQL de su elección mediante vectores no especificados en (a) sendarticle.asp y (b) printarticle.asp, y el parámetro ID a (c) index.asp y (d) preferences.asp, vectores diferentes que… | |
| Modificada | Alta (7.5) | 3.4% | — | Borland Software C++ BuilderBorland Software C BuilderBorland Software DelphiBorland Software Developer Studio+2 | 1/12/2006 | 16/6/2026 | Desbordamiento del buffer basado en pilas en el Borland idsql32.dll 5.1.0.4, como el usado en el RevilloC MailServer, la 5.2.0.2 como el usado en el Developer Studio 2006 y posiblemente otras versiones, permite a atacantes remotos ejecutar código de su elección a través de la declaración de una sentencia larga en SQL… | |
| Modificada | Alta (7.6) | 52% | 💥 Exploit | Businessobjects Crystal Reports XIMicrosoft Visual Studio .net | 28/11/2006 | 16/6/2026 | Desbordamiento de búfer basado en pila en Visual Studio Crystal Reports para Microsoft Visual Studio .NET 2002 y 2002 SP1; .NET 2003 y 2003 SP1; y 2005 y 2005 SP1 (anteriormente Business Objects Crystal Reports XI Professional) permite a atacantes remotos con la ayuda del usuario, ejecutar código de su elección… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Superfreaker Studios Ustore | 14/11/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en detail.asp en Superfreaker Studios UStore 1.0 permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro ID. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Superfreaker Studios Upublisher | 14/11/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en viewarticle.asp en Superfreaker Studios UPublisher 1.0 permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro ID. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Superfreaker Studios Usupport | 14/11/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en detail.asp en Superfreaker Studios USupport 1.0 permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro id. | |
| Modificada | Alta (7.6) | 2.3% | — | Studio Achtundachtzig Bloomooweb Activex Control | 3/11/2006 | 16/6/2026 | El control ActiveX BlooMooWeb (AidemATL.dll) permite a atacantes remotos (1) descargar ficheros de su elección mediante una URL en el parámetro bstrUrl en la función BW_DownloadFile, (2) ejecutar ficheros locales de su elección mediante una ruta de fichero en el parámetro bstrParams en el método BW_LaunchGame, y (3)… | |
| Modificada | Media (6.8) | 46% | 💥 Exploit | Microsoft Visual Studio .net | 1/11/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en zonas cruzadas en el Control ActiveX (WmiScriptUtils.dll) del WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) en el Microsoft Visual Studio 2005 permite atacantes remotos evitar las restricciones de la zona de Internet y ejecutar código de su elección instanciando… | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Microsoft Visual Studio | 31/8/2006 | 16/6/2026 | Microsoft Visual Studio 6.0 permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria) y posiblemente ejecutar código arbitrario instanciando objetos Visual Studio 6.0 ActiveX COM en Internet Explorer, incluyendo (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, y (5)… | |
| Modificada | Alta (7.5) | 5.0% | — | Sony Sonicstage Mastering Studio | 21/8/2006 | 16/6/2026 | Desbordamiento de búfer en la funcionalidad de importación de proyecto en Sony SonicStage Mastering Studio 1.1.00 hasta 2.2.01 permite a atacantes remotos ejecutar código de su elección mediante un archivo SMP manipulado. | |
| Modificada | Alta (7.5) | 1.3% | — | SD Studio CMS | 28/7/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en index.php en SD Studio CMS permite a atacantes remotos ejecutar comandos SQL de su elección a través de los parámetros 1) news_id, (2) tid, y (3) page_id. | |
| Modificada | Alta (7.5) | 4.5% | — | Pumpkin Studios WarzonePumpkin Studios Warzone Resurrection | 25/7/2006 | 16/6/2026 | Desbordamiento de búfer basado en pila en Warzone 2100 y Warzone Resurrection 2.0.3 y anteriores permiten a atacantes remotos ejecutar código de su elección a través de un mensaje (1) long manejado por la función recvTextMessage en multiplay.c o un (2) manejador de nombre de fichero por la función NETrecvFile en… | |
| Modificada | Media (4.3) | 1.4% | — | Virtual Design Studios Vlbook | 27/6/2006 | 16/6/2026 | Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en index.php en vlbook v1.02, permite a atacantes remotos inyectar secuencias de comandos web de su elección a través del parámetro "message". | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | Qjstudios Qjforum | 30/5/2006 | 16/6/2026 | SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the uName parameter. | |
| Modificada | Media (5.8) | 1.3% | — | Faktorystudios Easyevent | 9/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in easyEvent 1.2 allows remote attackers to inject arbitrary web script or HTML via the curr_year parameter. | |
| Modificada | Baja (3.7) | 0.38% | — | SUN Java Studio Enterprise | 19/4/2006 | 16/6/2026 | Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors. | |
| Modificada | Media (5) | 2.9% | — | Jabberstudio Jabberd | 21/3/2006 | 16/6/2026 | The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza". | |
| Modificada | Media (5.1) | 23% | 💥 Exploit | Microsoft Visual InterdevMicrosoft Visual Studio | 7/3/2006 | 16/6/2026 | Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attackers to execute arbitrary code via a long DataProject field in a (1) Visual Studio Database Project File (.dbp) or (2) Visual Studio Solution (.sln). | |
| Modificada | Media (5) | 1.2% | — | Cerulean Studios Trillian | 4/2/2006 | 16/6/2026 | Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via an AIM message containing the Mac encoded Rich Text Format (RTF) escape sequences (1) \'d1, (2) \'d2, (3) \'d3, (4) \'d4, and (5) \'d5. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Ashwebstudio Ashnews | 2/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (5.1) | 19% | 💥 Exploit | Microsoft Visual Studio .net | 12/1/2006 | 16/6/2026 | By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file. | |
| Modificada | Alta (7.2) | 1.2% | — | Adobe CaptivateAdobe ContributeAdobe DirectorAdobe Dreamweaver+5 | 31/12/2005 | 16/6/2026 | Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System. | |
| Modificada | Media (5) | 1.6% | — | Cerulean Studios Trillian | 5/10/2005 | 16/6/2026 | Cerulean Studios Trillian 3.0 allows remote attackers to cause a denial of service (crash) via a reverse direct connection from a different client, as demonstrated using LICQ. | |
| Modificada | Alta (7.5) | 3.3% | — | Image-line Software FL Studio | 28/9/2005 | 16/6/2026 | Heap-based buffer overflow in Image-Line Software FL Studio 5.0.1 allows remote attackers to execute arbitrary code via a .flp file that contains a long path to a (1) .mid or (2) .wav file. | |
| Modificada | Media (4.3) | 1.00% | — | Riverdark Studios RSS Syndicator Module | 27/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) topic parameters. |