Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 247 respecto a la semana anterior
Críticas / altas1338▼ 91 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)2.0%—Eric Integrated Development Environment27/9/200516/6/2026
Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit."
ModificadaMedia (5)1.3%—Interchange Development Group Interchange27/9/200516/6/2026
Unspecified vulnerability in Interchange 5.0.1 allows attackers 4.9.3, 5.0 before 5.0.2, and 5.2, when a catalog has been created using the (1) "mike", (2) "standard", or (3) "foundation" demo, allows attackers to inject Interchange Tag Language (ITL) elements into the forum/submit.html page.
ModificadaAlta (7.5)1.9%—Interchange Development Group Interchange27/9/200516/6/2026
SQL injection vulnerability in pages/forum/submit.html in Interchange 4.9.3 up to 5.2.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaAlta (7.5)3.1%💥 ExploitAzerbaijan Development Group Azdgdating16/9/200516/6/2026
Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP commands via ".." sequences and "%00" (trailing null byte) characters in the l parameter, which is used in an include_once statement.
ModificadaMedia (5)7.2%💥 ExploitWhitsoft Development Slimftpd8/9/200516/6/2026
SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overflow or off-by-one error.
ModificadaAlta (7.5)21%💥 ExploitDameware Development Mini Remote Control Server8/9/200516/6/2026
Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary code via the username.
ModificadaAlta (7.5)15%💥 ExploitELM Development Group ELM23/8/200516/6/2026
Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote attackers to execute arbitrary code via an e-mail message with a long Expires header.
ModificadaAlta (7.5)2.6%💥 ExploitGravity Board X Development Team Gravity Board X16/8/200516/6/2026
SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field.
ModificadaMedia (4.3)1.3%—Gravity Board X Development Team Gravity Board X16/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Gravity Board X (GBX) 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the board_id parameter to deletethread.php or (2) the template.
ModificadaMedia (5)1.2%—Gravity Board X Development Team Gravity Board X16/8/200516/6/2026
Gravity Board X (GBX) 1.1 allows remote attackers to obtain sensitive information via (1) a 1 in the perm parameter to deletethread.php or a direct request to (2) ban.php, (3) addnews.php, (4) banned.php, (5) boardstats.php, (6) adminform.php, (7) /forms/admininfo.php, (8) /forms/announcements.php, (9)…
ModificadaAlta (7.5)5.1%💥 ExploitGravity Board X Development Team Gravity Board X16/8/200516/6/2026
Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file.
ModificadaAlta (9.3)2.7%—VIM Development Group VIM26/7/200516/6/2026
vim 6.3 anterior a la 6.3.082, con "modelines" habilitado, permite que atacantes remotos con la implicación del usuario que ejecuten comandos arbitrarios mediante metacaracteres de shell en los comandos "glob" o "expand" de una expresión "foldexpr".
ModificadaAlta (7.2)46%💥 ExploitWhitsoft Development Slimftpd26/7/200516/6/2026
Desbordamiento de búfer en SlimFTPd 3.15 y 3.16 permite que usuarios remotos autentificados ejecuten código arbitrario mediante un nombre de directorio largo en los comandos LIST, DELE o RNFR.
ModificadaMedia (4.6)0.51%—Oracle Jdeveloper18/7/200516/6/2026
Oracle JDeveloper 9.0.4, 9.0.5, y 10.1.2 pasa el password en texto plano como parámetro cuando arranca "sqlplus", lo que permite que usuarios locales obtengan información confidencial.
ModificadaBaja (2.1)0.87%—Oracle Jdeveloper18/7/200516/6/2026
Oracle JDeveloper 9.0.4, 9.0.5, y 10.1.2 almacena passwords como texto plano en 1) IDEConnections.xml, (2) XSQLConfig.xml y (3) settings.xml. Esto permite que usuarios locales obtengan información confidencial.
ModificadaAlta (7.5)1.2%💥 ExploitLighthouse Development Squirrelcart2/5/200516/6/2026
SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.
ModificadaMedia (5)3.5%💥 ExploitYager Development Yager Game2/5/200516/6/2026
Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game header that provides less data than indicated by the length.
ModificadaMedia (4.3)2.0%💥 ExploitDevellion Cubecart2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.
ModificadaMedia (5)3.0%💥 ExploitDevellion Cubecart2/5/200516/6/2026
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP…
ModificadaMedia (4.3)4.8%💥 ExploitDevellion Cubecart2/5/200516/6/2026
index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.
ModificadaBaja (2.1)0.35%—Dameware Development Dameware NT UtilitiesDameware Development Miniremote Control2/5/200516/6/2026
The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain sensitive information.
ModificadaMedia (5)1.4%—Devellion Cubecart2/5/200516/6/2026
CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which…
ModificadaMedia (4.3)1.7%💥 ExploitAzerbaijan Development Group Azdgdating2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaMedia (5)8.3%💥 ExploitDevellion Cubecart2/5/200516/6/2026
Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.
ModificadaMedia (6.4)13%💥 ExploitYager Development Yager Game2/5/200516/6/2026
Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data.