Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.5% | 💥 Exploit | Michal Marcinkowski Soldat Dedicated ServerMichal Marcinkowski Soldat Game Server | 25/8/2007 | 16/6/2026 | Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via (1) a long string to the file transfer port or (2) a long chat message, or (3) a server denial of service (continuous beep and slowdown) via a string containing many… | |
| Modificada | Alta (10) | 5.0% | 💥 Exploit | Marcello Vitagliano Meganoides News | 21/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. | |
| Modificada | Media (5) | 0.97% | — | March Networks 3108 DVRMarch Networks 3204 DVRMarch Networks 4210 DVRMarch Networks 4310 DVR+1 | 12/2/2007 | 16/6/2026 | Unspecified vulnerability in March Networks DVR 3000 and 4000 Digital Video Recorders allows attackers to cause an unspecified denial of service. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.3% | — | DE Marchi Daniele Quickcam | 31/12/2006 | 16/6/2026 | The qcamvc_video_init function in qcamvc.c in De Marchi Daniele QuickCam VC Linux device driver (aka quickcam-vc) 1.0.9 and earlier does not properly check a boundary, triggering memory corruption, which might allow attackers to execute arbitrary code via a crafted QuickCam object. | |
| Modificada | Media (5) | 1.2% | — | Apple BomarchivehelperApple MAC OS XApple MAC OS X Server | 7/12/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the… | |
| Modificada | Baja (2.6) | 2.6% | 💥 Exploit | Marc Giombetti Phppowercards | 20/10/2006 | 16/6/2026 | Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[from], (5) picture, (6) comment, or (7) sessionID parameter, as… | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Marc Logemann More.groupware | 21/9/2006 | 16/6/2026 | SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbitrary SQL commands via the new_calendarid parameter. | |
| Modificada | Alta (7.5) | 2.9% | — | Marc Cagninacci Mclinkscounter | 19/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the… | |
| Modificada | Alta (7.5) | 2.7% | — | Marc Lehmann Rxvt-unicode | 2/5/2005 | 16/6/2026 | Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences. | |
| Modificada | Media (4.6) | 0.34% | — | Marc Lehmann Rxvt-unicode | 31/12/2004 | 16/6/2026 | RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows local users to access the terminals of other users and possibly gain privileges. | |
| Modificada | Alta (7.5) | 1.2% | — | Demarc Security Puresecure | 21/5/2003 | 16/6/2026 | Demarc Puresecure 1.6 stores authentication information for the logging server in plaintext, which allows attackers to steal login names and passwords to gain privileges. | |
| Modificada | Alta (10) | 6.6% | 💥 Exploit | Marcos Luiz Onisto LIB CGI | 31/12/2002 | 16/6/2026 | Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Alta (10) | 3.4% | — | Marcus S. Xenakis Directory.php | 26/7/2002 | 16/6/2026 | Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter. | |
| Modificada | Alta (10) | 2.1% | 💥 Exploit | Demarc Security Puresecure | 3/7/2002 | 16/6/2026 | Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie. | |
| Modificada | Alta (7.5) | 3.6% | — | Marcus S. Xenakis Unix Manual | 15/12/2001 | 16/6/2026 | manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters. | |
| Modificada | Media (5) | 2.3% | — | Marc Logemann More.groupware | 2/10/2001 | 16/6/2026 | More.groupware PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | |
| Modificada | Media (5) | 1.6% | — | Marconi Forethought | 4/9/2001 | 16/6/2026 | Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Marconi ForethoughtMarconi Asx-1000 | 3/5/2001 | 16/6/2026 | Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set. | |
| Modificada | Alta (7.5) | 2.5% | — | Marc Schaefer Ptylogin | 12/3/2001 | 16/6/2026 | ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords. |