Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 43% | 💥 Exploit | Chillcreations COM Ccnewsletter | 2/2/2010 | 16/6/2026 | Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php. | |
| Modificada | Alta (9.3) | 4.8% | 💥 Exploit | Chilkatsoft Chilkat Imap Activex Control | 21/8/2009 | 16/6/2026 | Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method. | |
| Modificada | Alta (9.3) | 5.7% | 💥 Exploit | Chilkatsoft Chilkat Socket | 12/8/2009 | 16/6/2026 | Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll 2.3.1.1 allows remote attackers to overwrite arbitrary files via the SaveLastError method. NOTE: this might be related to CVE-2008-1647. | |
| Modificada | Media (6.5) | 0.90% | 💥 Exploit | Haudenschilt Family Connections CMS | 8/6/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter to profile.php, (3) pid parameter to gallery/index.php, and the (4)… | |
| Modificada | Alta (9.3) | 41% | 💥 Exploit | Chilkat Software Chilkat Crypt Activex Control | 10/11/2008 | 16/6/2026 | Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in… | |
| Modificada | Media (6.8) | 4.7% | 💥 Exploit | Chilkat Software Mail | 15/10/2008 | 16/6/2026 | Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pathname to the SaveLastError method. | |
| Modificada | Alta (7.5) | 5.9% | 💥 Exploit | Chilkat Software FTP | 15/10/2008 | 16/6/2026 | Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pathname in the SavePkcs8File method. | |
| Modificada | Alta (9.3) | 8.7% | 💥 Exploit | Chilkat Software Chilkat XML Activex Control | 30/9/2008 | 16/6/2026 | The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Haudenschilt Battlenet Clan Script | 8/8/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in Battle.net Clan Script 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) showmember parameter in a members action and the (2) thread parameter in a board action. NOTE: vector 1 might be the same as CVE-2008-2522. | |
| Modificada | Media (6.5) | 0.86% | 💥 Exploit | Haudenschilt Family Connections CMS | 30/6/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated users to execute arbitrary SQL commands via the (1) address parameter to addressbook.php, the (2) getnews parameter to familynews.php, and the (3) poll_id parameter to home.php in a results action. | |
| Modificada | Media (6.8) | 0.95% | 💥 Exploit | Haudenschilt Battlenet Clan Script | 3/6/2008 | 16/6/2026 | SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showmember parameter in a members action. | |
| Modificada | Alta (7.5) | 1.5% | — | Chilkat Software Chicomas | 30/4/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter to the default URI under install/. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal… | |
| Modificada | Alta (7.5) | 1.5% | — | Chilkat Software Chicomas | 30/4/2008 | 16/6/2026 | Directory traversal vulnerability in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the operation parameter to the default URI under install/. | |
| Modificada | Alta (9.3) | 7.0% | 💥 Exploit | Chilkat Software Chilkathttp Activex | 2/4/2008 | 16/6/2026 | The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (4.4) | 0.34% | — | ONE Laptop PER Child Olpc Linux | 12/9/2007 | 16/6/2026 | JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enabled, does not properly store permissions during (1) inode creation or (2) ACL setting, which might allow local users to access restricted files or directories after a remount of a filesystem, related… | |
| Modificada | Alta (10) | 8.9% | 💥 Exploit | Haudenschilt Family Connections CMS | 14/8/2007 | 16/6/2026 | index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Chilkat Software ASP String | 8/8/2007 | 16/6/2026 | Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveToFile method, a different vulnerability than CVE-2007-3633. | |
| Modificada | Media (6.4) | 2.9% | 💥 Exploit | Chilkat Software Chilkat ZIP Activex Control | 10/7/2007 | 16/6/2026 | Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Ryan Haudenschilt Battle.net Clan Script | 10/4/2007 | 16/6/2026 | SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Baja (2.6) | 1.2% | — | Ncipher ChilNcipher Mscapi CSPNcipher Software CD | 9/3/2006 | 16/6/2026 | nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an attacker to crack the private key in significantly less time than a brute force attack. | |
| Modificada | Alta (7.5) | 1.5% | — | Archilles Newsworld | 2/11/2005 | 16/6/2026 | Archilles Newsworld before 1.5.0-rc1 stores (1) account.nwd and (2) session.nwd under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames, hashed passwords, and session IDs, and gain privileges. | |
| Modificada | Crítica (9.8) | 2.3% | — | Archilles Newsworld | 2/11/2005 | 16/6/2026 | admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument. | |
| Modificada | Alta (10) | 1.7% | — | Jorg Schilling SDD | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the remote tape support (remote.c) in the RMT client for Jorg Schilling sdd 1.28 and 1.31 has unknown impact and attack vectors. | |
| Modificada | Alta (7.2) | 0.43% | — | Joerg Schilling Star Tape Archiver | 23/12/2004 | 16/6/2026 | Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program. |