Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1725 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.95%—Invision Power Services Invision Power Board31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.
ModificadaAlta (7.5)4.4%💥 ExploitInvision Power Services Invision Power TOP Site List31/12/200416/6/2026
SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.
ModificadaAlta (7.5)4.9%💥 ExploitInvision Power Services Invision Gallery31/12/200416/6/2026
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.
ModificadaMedia (5)1.9%—Geovision Geohttpserver31/12/200416/6/2026
The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.
ModificadaMedia (5)1.4%—Geovision Geohttpserver31/12/200416/6/2026
GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).
ModificadaMedia (4.3)1.1%—Invision Power Services Invision Power Board31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.
ModificadaAlta (7.5)3.8%—PAN Vision I.g.i-2 Covert Strike31/12/200416/6/2026
Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands.
ModificadaMedia (5)1.7%—Invision Power Services Invision Board23/11/200416/6/2026
Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message.
ModificadaMedia (6.8)5.6%—Invision Power Services Invision Board23/11/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.
ModificadaAlta (10)2.4%—Invision Power Services Invision Board23/11/200416/6/2026
SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.
ModificadaAlta (9.3)49%💥 ExploitMicrosoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+2028/9/200416/6/2026
Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria.
ModificadaMedia (5)7.5%💥 ExploitActivision Call OF DutyActivision Call OF Duty United Offensive5/9/200416/6/2026
Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection mechanism. NOTE: this issue might overlap CVE-2005-0430.
ModificadaAlta (7.5)1.4%—Invision Power Services Invision Board3/1/200416/6/2026
SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.
ModificadaMedia (6.8)4.0%💥 ExploitInvision Power Services Invision Power Board31/12/200316/6/2026
ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.
ModificadaMedia (5)1.2%—Invision Power Services Invision Board31/12/200316/6/2026
Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.
ModificadaAlta (10)55%💥 ExploitMicrosoft OfficeMicrosoft ProjectMicrosoft VisioMicrosoft Visual Basic20/10/200316/6/2026
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.
ModificadaMedia (5)2.0%—Invision Power Services Invision Board11/10/200216/6/2026
El procedimiento de instalación en Invision Board sugiere que los usuarios instalen el programa phpinfo.php en la raíz del web, lo que filtra información sensible como nombres de rutas, información del SO, y configuración de php.
ModificadaAlta (7.5)43%—Allume Systems Division Stuffit ExpanderIBM Lotus NotesVerity Keyview Viewing SDKWinzip+310/10/200216/6/2026
Desbordamiento de búfer en la capacidad ZIP de múltiples productos permite a atacantes remotos causar una denegación de servicio o ejecutar código arbitrario mediante ficheros ZIP que contienen nombres de ficheros largos, incluyendo Microsoft Windows 98 con el paquete Plus! Windows XP Windows Me Lotus Notes R4 a R6…
ModificadaAlta (10)2.6%—Nara Vision Kebi Community8/12/200116/6/2026
Kebi WebMail allows remote attackers to access the administrator menu and gain privileges via the /a/ hidden directory, which is installed under the web document root.
ModificadaMedia (5)1.3%—Navision Financials Server18/6/200116/6/2026
Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.
ModificadaMedia (5)1.3%—Navision Financials Server18/6/200116/6/2026
Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.
ModificadaMedia (5)1.4%—Broadvision One-to-one Enterprise Server16/2/200116/6/2026
BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.
ModificadaAlta (7.2)0.41%—Lexmark Markvision16/2/200116/6/2026
Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands.
ModificadaAlta (7.2)1.1%💥 ExploitTridia Doublevision14/11/200016/6/2026
Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument.
ModificadaMedia (5)1.7%—Virtual Vision FTP Browser12/7/200016/6/2026
ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack.