Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 5.9% | — | Mathi Peamp | 8/7/2009 | 16/6/2026 | Buffer overflow in amp.exe in Brothersoft PEamp 1.02b allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.0% | — | Mathieu Vidal MV VOX Populi | 27/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Vox populi (mv_vox_populi) extension 0.3.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Wordpress Math Comment Spam Protection Plugin | 10/1/2008 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to… | |
| Modificada | Media (4.3) | 1.9% | — | Wordpress Math Comment Spam Protection Plugin | 10/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to… | |
| Modificada | Media (4.6) | 0.32% | — | PTC Mathcad | 18/10/2007 | 16/6/2026 | The "Protect Worksheet" functionality in Mathsoft Mathcad 12 through 13.1, and PTC Mathcad 14, implements file access restrictions via a protection element in a gzipped XML file, which allows attackers to bypass these restrictions by removing this element. | |
| Modificada | Media (4.4) | 0.33% | — | Mathsoft Mathcad | 23/2/2007 | 16/6/2026 | Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify… | |
| Modificada | Media (5) | 1.4% | — | Xiao Gang WWW Interactive Mathematics Server | 23/10/2006 | 16/6/2026 | Unspecified vulnerability in XIAO Gang WWW Interactive Mathematics Server (WIMS) before 3.60 allows remote attackers to modify unspecified data via unspecified vectors involving "variable rights." | |
| Modificada | Media (5) | 14% | — | TDC Cryptomathic Cenroll Activex Control | 9/5/2006 | 16/6/2026 | Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary code via vectors related to the TDC Digital signature. | |
| Modificada | Media (5.5) | 0.36% | — | Mathopd | 2/5/2005 | 16/6/2026 | The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to overwrite arbitrary files via a symlink attack on dump files that are triggered by a SIGWINCH signal. | |
| Modificada | Alta (7.5) | 14% | — | Mathopd | 31/12/2003 | 16/6/2026 | Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path. | |
| Modificada | Media (4.6) | 0.32% | — | Stichting Mathematisch Centrum Nethack | 24/7/2003 | 16/6/2026 | nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code. | |
| Modificada | Media (5) | 5.7% | — | Wolfram Research Webmathematica | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the MSPStoreID parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Wolfram Research Mathematica | 13/2/2002 | 16/6/2026 | The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to bypass access control (specified by the -restrict argument) and steal a license via a client request that includes the name of a host that is allowed to obtain the license. | |
| Modificada | Media (5) | 1.6% | — | Wolfram Research Mathematica | 30/7/2001 | 16/6/2026 | The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests. |