Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3077▲ 447 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1781 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.7%💥 ExploitMichael Dean Double Choco Latte24/3/200516/6/2026
Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in (1) functions.inc.php or (2) main.php, which causes code to be injected into an eval statement.
ModificadaMedia (5)3.1%💥 ExploitLucasarts Star Wars Battlefront10/1/200516/6/2026
Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.
ModificadaMedia (5)3.3%💥 ExploitDigital Illusions Battlefield 1942Digital Illusions Battlefield Vietnam10/1/200516/6/2026
Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference.
ModificadaMedia (5)3.4%💥 ExploitLucasarts Star Wars Battlefront10/1/200516/6/2026
Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.
ModificadaMedia (4.3)4.0%💥 ExploitGeeos Team Gattaca Server 200331/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.
ModificadaMedia (5)1.7%—Opentools Attachment MOD31/12/200416/6/2026
Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename.
ModificadaMedia (5)3.4%💥 ExploitTargem Games Battle Mages31/12/200416/6/2026
Targem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incomplete data, which causes the server to enter an infinite loop while waiting to read the rest of the data that is not sent.
ModificadaMedia (5)4.5%💥 ExploitGeeos Team Gattaca Server 200331/12/200416/6/2026
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.
ModificadaAlta (7.5)1.3%—Natterchat31/12/200416/6/2026
SQL injection vulnerability in NatterChat 1.12 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (5)0.84%—Matthew Phillips Sticker31/12/200416/6/2026
The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.
ModificadaAlta (7.5)2.9%—Opentools Attachment MOD31/12/200416/6/2026
Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
ModificadaMedia (5)1.9%—ChatterboxAI31/12/200416/6/2026
ChatterBox 2.0 allows remote attackers to cause a denial of service (server crash) via a malformed request to the server, as demonstrated using "aaaaaa".
ModificadaMedia (4)3.3%💥 ExploitGeeos Team Gattaca Server 2003AI31/12/200416/6/2026
POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.
ModificadaAlta (10)1.9%—Matthew Skala Rippy THE Aggregator31/12/200416/6/2026
Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors and impact, possibly related to the "user-controlled filter."
ModificadaMedia (5)1.8%—Geeos Team Gattaca Server 200331/12/200416/6/2026
Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).
ModificadaMedia (5)8.0%💥 ExploitGeeos Team Gattaca Server 200331/12/200416/6/2026
Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "\", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en".
ModificadaAlta (10)7.5%—Seattle LAB Software Slmail PRO23/11/200416/6/2026
Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a long HTTP sub-version.
ModificadaAlta (10)5.0%—Seattle LAB Software Slmail PRO23/11/200416/6/2026
Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll.
ModificadaMedia (5)1.6%—Toplayer Attack Mitigator22/7/200416/6/2026
Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests.
ModificadaMedia (4.6)0.42%—Robert Hyatt Crafty29/3/200416/6/2026
Desbordamiento de búfer en main.c de Crafty 19.3 permite a usuarios locales ganar privilegios del grupo "games" mediante argumentos de línea de comandos largos.
ModificadaMedia (4.8)0.51%—Bharat Mediratta Gallery31/12/200316/6/2026
Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.
ModificadaAlta (7.5)4.5%💥 ExploitElectronic Arts Battlefield 194231/12/200316/6/2026
Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.
ModificadaMedia (4.3)1.9%—Matt Wright WwwboardAI31/12/200316/6/2026
Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.
ModificadaAlta (7.5)1.4%💥 ExploitAttila-php.net Attilaphp20/10/200316/6/2026
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.
ModificadaAlta (7.1)2.2%💥 ExploitSplatt Forum18/8/200316/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Splatt Forum permite a atacantes remotos insertar HTML y script web arbitrarios mediante el campo de icono de envio (image_subject).