Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 2.2% | — | Kmonos Xacrett | 19/10/2010 | 16/6/2026 | Untrusted search path vulnerability in XacRett before 50 allows attackers to execute arbitrary code via a Trojan horse executable file, related to the explorer.exe filename and use of Windows Explorer. | |
| Modificada | Media (6.8) | 1.9% | — | Mono-project Libgdiplus | 24/8/2010 | 16/6/2026 | Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, related to the gdip_load_tiff_image function in tiffcodec.c; (2) a crafted JPEG file, related to the gdip_load_jpeg_image_internal function in jpegcodec.c; or (3) a crafted BMP file,… | |
| Modificada | Media (4.3) | 1.9% | — | Mono | 27/5/2010 | 16/6/2026 | The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project. | |
| Modificada | Media (5) | 6.4% | — | IBM Websphere Application ServerMono Project MonoOracle Application ServerOracle BEA Product Suite+1 | 14/7/2009 | 16/6/2026 | The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3,… | |
| Modificada | Media (4.3) | 7.1% | 💥 Exploit | MonoMono Project Mono | 4/9/2008 | 16/6/2026 | CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string. | |
| Modificada | Media (4.3) | 1.6% | — | MonoMono Project Mono | 31/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton… | |
| Modificada | Alta (7.5) | 3.6% | — | Mono | 2/11/2007 | 16/6/2026 | Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods. | |
| Modificada | Media (5) | 1.3% | — | Mono | 18/10/2007 | 16/6/2026 | StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a trailing (1) space or (2) dot, which is not properly handled by XSP. | |
| Modificada | Alta (9.3) | 5.2% | — | Monolith Productions First Encounter Assault Recon | 6/10/2007 | 16/6/2026 | Multiple format string vulnerabilities in the Monolith Lithtech engine, as used by First Encounter Assault Recon (F.E.A.R.) 1.08 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet… | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Mono XSP | 21/12/2006 | 16/6/2026 | The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20. | |
| Modificada | Media (6.2) | 0.46% | — | Mono | 10/10/2006 | 16/6/2026 | The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack. | |
| Modificada | Media (5) | 3.9% | — | Mono XSPSuse Open Enterprise ServerSuse Linux | 12/9/2006 | 16/6/2026 | Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request. | |
| Modificada | Baja (3.7) | 0.32% | — | Monotone | 12/3/2006 | 16/6/2026 | Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into the "MT" bookkeeping directory, which could allow context-dependent attackers to execute arbitrary Lua programs as the… | |
| Modificada | Media (5) | 4.7% | 💥 Exploit | Monopd | 7/3/2006 | 16/6/2026 | server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output. | |
| Modificada | Media (4.3) | 16% | — | Microsoft .net FrameworkMono | 14/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<". | |
| Modificada | Baja (2.1) | 1.9% | 💥 Exploit | Freeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+7 | 31/12/2004 | 16/6/2026 | Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Monolith Productions Contract JackMonolith Productions NO ONE Lives Forever 2Monolith Productions Tron | 31/12/2004 | 16/6/2026 | The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that… | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Monolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions NO ONE Lives ForeverMonolith Productions Shogo | 31/12/2004 | 16/6/2026 | Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query. |