Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)4.0%💥 ExploitGeeos Team Gattaca Server 200331/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.
ModificadaMedia (5)1.6%—Hired TeamAI31/12/200416/6/2026
Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.
ModificadaMedia (5)1.7%—NEW Media Generation Hired Team Trial31/12/200416/6/2026
Format string vulnerability in the game console in Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a message.
ModificadaAlta (7.5)1.1%—NEW Media Generation Hired Team Trial31/12/200416/6/2026
Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.
ModificadaMedia (5)1.8%—Geeos Team Gattaca Server 200331/12/200416/6/2026
Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).
ModificadaMedia (5)1.7%—NEW Media Generation Hired Team Trial31/12/200416/6/2026
Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (game interruption) via a malformed UDP packet sent to a game port, such as port 29200.
ModificadaMedia (5)2.8%💥 PoCDelegateDnrdDON Moore MydnsMaradns+1131/12/200416/6/2026
Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by…
ModificadaMedia (5)8.0%💥 ExploitGeeos Team Gattaca Server 200331/12/200416/6/2026
Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "\", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en".
ModificadaAlta (7.5)7.3%💥 ExploitAlexphpteam Alex Guestbook31/12/200416/6/2026
PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.
ModificadaMedia (4)3.3%💥 ExploitGeeos Team Gattaca Server 2003AI31/12/200416/6/2026
POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.
ModificadaMedia (5.8)2.2%💥 ExploitSerena Software Serena Teamtrack31/12/200416/6/2026
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.
ModificadaMedia (5)4.5%💥 ExploitGeeos Team Gattaca Server 200331/12/200416/6/2026
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.
ModificadaMedia (5)1.5%—Qualiteam X-cart23/11/200416/6/2026
Vulnerabilidad de atravesamiento de directorios en X-Cart 3.4.3 permite que atacantes remotos vean ficheros arbitrarios mediante un argumento .. (punto punto) a shop_closed_file de auth.php
ModificadaMedia (5)6.9%💥 ExploitQualiteam X-cart23/11/200416/6/2026
X-Cart 3.4.3 permite que atacantes remotos obtengan información relevante mediante el parámetro de modo en los comandos phpinfo o perlinfo.
ModificadaAlta (10)6.0%💥 ExploitQualiteam X-cart23/11/200416/6/2026
X-Cart 3.4.3 permite que atacantes remotos ejecuten comandos arbitrarios a través del argumento perl_binary en upgrade.php o general.php.
ModificadaMedia (5)1.6%—Singularity Software Team Factor23/11/200416/6/2026
Team Factor 1.25 and earlier allows remote attackers to cause a denial of service (crash) via a packet that uses a negative number to specify the size of the data block that follows, which causes Team Factor to read unallocated memory.
ModificadaBaja (2.1)0.93%💥 ExploitTHE PAX Team PAX LinuxGentoo Linux2/5/200416/6/2026
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.
ModificadaAlta (7.5)83%💥 ExploitMicrosoft Frontpage Server ExtensionsMicrosoft Sharepoint Team ServicesMicrosoft Windows 2000Microsoft Windows XP15/12/200316/6/2026
Desbordamiento de búfer en la funcionalidad de depuración en fp30reg.dll de Microsoft FrontPage Server Extensions 2000 y 2002 permite a atacantes remotos ejecutar código mediante una cierta petición en trozos codificada.
ModificadaMedia (5)37%—Microsoft Frontpage Server ExtensionsMicrosoft Sharepoint Team ServicesMicrosoft Windows 2000Microsoft Windows XP15/12/200316/6/2026
Vulnerabilidad desconocida en el intérprete SmartHTML interpreter (shtml.dll) en Microsoft FrontPage Server Extensions 2000 y 2002, y Microsoft SharePoint Team Services 2002, permite a atacantes remotos causar una denegación de servicio (fallo de respuesta) mediante una cierta petición.
ModificadaAlta (7.5)2.8%💥 ExploitCroteam Serioussam30/10/200316/6/2026
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.
ModificadaAlta (7.2)1.5%💥 ExploitSlrn Development Team Slrn12/8/200216/6/2026
Desbordamiento de búfer en slrnpull para el paquete SLRN, cuando tiene activo el bit setuid o setgid, permite que usuarios locales obtengan privilegios mediante un argumento -d (SPOOLDIR) largo.
ModificadaAlta (7.5)2.1%—Slrn Development Team Slrn24/9/200116/6/2026
Binary decoding feature of slrn 0.9 and earlier allows remote attackers to execute commands via shell scripts that are inserted into a news post.
ModificadaAlta (10)17%💥 ExploitPhplib Team Phplib21/7/200116/6/2026
prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.
ModificadaAlta (10)1.5%—Phpwebsite Development Team Phpwebsite19/7/200116/6/2026
Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges.
ModificadaAlta (7.5)1.1%—Twig Development Team Twig19/7/200116/6/2026
Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.