Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)3.5%💥 ExploitMichal Marcinkowski Soldat Dedicated ServerMichal Marcinkowski Soldat Game Server25/8/200716/6/2026
Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via (1) a long string to the file transfer port or (2) a long chat message, or (3) a server denial of service (continuous beep and slowdown) via a string containing many…
ModificadaAlta (10)5.0%💥 ExploitMarcello Vitagliano Meganoides News21/2/200716/6/2026
PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter.
ModificadaMedia (5)0.97%—March Networks 3108 DVRMarch Networks 3204 DVRMarch Networks 4210 DVRMarch Networks 4310 DVR+112/2/200716/6/2026
Unspecified vulnerability in March Networks DVR 3000 and 4000 Digital Video Recorders allows attackers to cause an unspecified denial of service. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)2.3%—DE Marchi Daniele Quickcam31/12/200616/6/2026
The qcamvc_video_init function in qcamvc.c in De Marchi Daniele QuickCam VC Linux device driver (aka quickcam-vc) 1.0.9 and earlier does not properly check a boundary, triggering memory corruption, which might allow attackers to execute arbitrary code via a crafted QuickCam object.
ModificadaMedia (5)1.2%—Apple BomarchivehelperApple MAC OS XApple MAC OS X Server7/12/200616/6/2026
Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the…
ModificadaBaja (2.6)2.6%💥 ExploitMarc Giombetti Phppowercards20/10/200616/6/2026
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[from], (5) picture, (6) comment, or (7) sessionID parameter, as…
ModificadaAlta (7.5)2.3%💥 ExploitMarc Logemann More.groupware21/9/200616/6/2026
SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbitrary SQL commands via the new_calendarid parameter.
ModificadaAlta (7.5)2.9%—Marc Cagninacci Mclinkscounter19/9/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the…
ModificadaAlta (7.5)2.7%—Marc Lehmann Rxvt-unicode2/5/200516/6/2026
Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences.
ModificadaMedia (4.6)0.34%—Marc Lehmann Rxvt-unicode31/12/200416/6/2026
RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows local users to access the terminals of other users and possibly gain privileges.
ModificadaAlta (7.5)1.2%—Demarc Security Puresecure21/5/200316/6/2026
Demarc Puresecure 1.6 stores authentication information for the logging server in plaintext, which allows attackers to steal login names and passwords to gain privileges.
ModificadaAlta (10)6.6%💥 ExploitMarcos Luiz Onisto LIB CGI31/12/200216/6/2026
Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a long argument.
ModificadaAlta (10)3.4%—Marcus S. Xenakis Directory.php26/7/200216/6/2026
Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.
ModificadaAlta (10)2.1%💥 ExploitDemarc Security Puresecure3/7/200216/6/2026
Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.
ModificadaAlta (7.5)3.6%—Marcus S. Xenakis Unix Manual15/12/200116/6/2026
manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters.
ModificadaMedia (5)2.3%—Marc Logemann More.groupware2/10/200116/6/2026
More.groupware PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
ModificadaMedia (5)1.6%—Marconi Forethought4/9/200116/6/2026
Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device.
ModificadaMedia (5)2.5%💥 ExploitMarconi ForethoughtMarconi Asx-10003/5/200116/6/2026
Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.
ModificadaAlta (7.5)2.5%—Marc Schaefer Ptylogin12/3/200116/6/2026
ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords.
Orbitaley — Vulnerabilidades