Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 447 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1781 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Michael Dean Double Choco Latte | 24/3/2005 | 16/6/2026 | Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in (1) functions.inc.php or (2) main.php, which causes code to be injected into an eval statement. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Digital Illusions Battlefield 1942Digital Illusions Battlefield Vietnam | 10/1/2005 | 16/6/2026 | Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Geeos Team Gattaca Server 2003 | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter. | |
| Modificada | Media (5) | 1.7% | — | Opentools Attachment MOD | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Targem Games Battle Mages | 31/12/2004 | 16/6/2026 | Targem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incomplete data, which causes the server to enter an infinite loop while waiting to read the rest of the data that is not sent. | |
| Modificada | Media (5) | 4.5% | 💥 Exploit | Geeos Team Gattaca Server 2003 | 31/12/2004 | 16/6/2026 | Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message. | |
| Modificada | Alta (7.5) | 1.3% | — | Natterchat | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in NatterChat 1.12 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (5) | 0.84% | — | Matthew Phillips Sticker | 31/12/2004 | 16/6/2026 | The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key. | |
| Modificada | Alta (7.5) | 2.9% | — | Opentools Attachment MOD | 31/12/2004 | 16/6/2026 | Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code. | |
| Modificada | Media (5) | 1.9% | — | ChatterboxAI | 31/12/2004 | 16/6/2026 | ChatterBox 2.0 allows remote attackers to cause a denial of service (server crash) via a malformed request to the server, as demonstrated using "aaaaaa". | |
| Modificada | Media (4) | 3.3% | 💥 Exploit | Geeos Team Gattaca Server 2003AI | 31/12/2004 | 16/6/2026 | POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands. | |
| Modificada | Alta (10) | 1.9% | — | Matthew Skala Rippy THE Aggregator | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors and impact, possibly related to the "user-controlled filter." | |
| Modificada | Media (5) | 1.8% | — | Geeos Team Gattaca Server 2003 | 31/12/2004 | 16/6/2026 | Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP). | |
| Modificada | Media (5) | 8.0% | 💥 Exploit | Geeos Team Gattaca Server 2003 | 31/12/2004 | 16/6/2026 | Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "\", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en". | |
| Modificada | Alta (10) | 7.5% | — | Seattle LAB Software Slmail PRO | 23/11/2004 | 16/6/2026 | Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a long HTTP sub-version. | |
| Modificada | Alta (10) | 5.0% | — | Seattle LAB Software Slmail PRO | 23/11/2004 | 16/6/2026 | Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll. | |
| Modificada | Media (5) | 1.6% | — | Toplayer Attack Mitigator | 22/7/2004 | 16/6/2026 | Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests. | |
| Modificada | Media (4.6) | 0.42% | — | Robert Hyatt Crafty | 29/3/2004 | 16/6/2026 | Desbordamiento de búfer en main.c de Crafty 19.3 permite a usuarios locales ganar privilegios del grupo "games" mediante argumentos de línea de comandos largos. | |
| Modificada | Media (4.8) | 0.51% | — | Bharat Mediratta Gallery | 31/12/2003 | 16/6/2026 | Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos. | |
| Modificada | Alta (7.5) | 4.5% | 💥 Exploit | Electronic Arts Battlefield 1942 | 31/12/2003 | 16/6/2026 | Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password. | |
| Modificada | Media (4.3) | 1.9% | — | Matt Wright WwwboardAI | 31/12/2003 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Attila-php.net Attilaphp | 20/10/2003 | 16/6/2026 | SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter. | |
| Modificada | Alta (7.1) | 2.2% | 💥 Exploit | Splatt Forum | 18/8/2003 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Splatt Forum permite a atacantes remotos insertar HTML y script web arbitrarios mediante el campo de icono de envio (image_subject). |