Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

179 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)3.4%—Kyoceramita Scanner File Utility28/8/200916/6/2026
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 does not restrict the filenames or extensions of uploaded files, which makes it easier for remote attackers to execute arbitrary code or overwrite files by leveraging CVE-2008-7110 and CVE-2008-7109.
ModificadaAlta (7.8)2.9%💥 ExploitKyoceramita Scanner File Utility28/8/200916/6/2026
Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. (dot dot) in a request.
ModificadaCrítica (9.8)4.1%—Kyoceramita Scanner File Utility28/8/200916/6/2026
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified program that does not prompt the user for a password.
ModificadaMedia (6.9)0.30%—Mailscanner3/12/200816/6/2026
mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) avast-autoupdate, and (4) f-prot-6-autoupdate scripts in /etc/MailScanner/autoupdate/; the (5)…
ModificadaMedia (6.9)0.30%—Mailscanner3/12/200816/6/2026
mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) panda-autoupdate.new, (4) trend-autoupdate.new, and (5) rav-autoupdate.new scripts in…
ModificadaMedia (6.9)0.33%—Debian Mailscanner18/11/200816/6/2026
trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/opr.ini.##### or (2) /tmp/lpt*.zip temporary file.
ModificadaMedia (4.3)1.1%—Internet Security Systems Internet Scanner29/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in the report interface in Internet Security Systems (ISS) Internet Scanner 7.0 Service Pack 2 Build 7.2.2005.52 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)8.1%💥 ExploitBitdefender Online Anti-virus Scanner30/11/200716/6/2026
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper…
ModificadaAlta (9.3)4.8%—Kaspersky LAB Online Scanner12/10/200716/6/2026
Multiple format string vulnerabilities in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) in Kaspersky Online Scanner before 5.0.98 allow remote attackers to execute arbitrary code via format string specifiers in "various string formatting functions," which trigger heap-based buffer overflows.
ModificadaAlta (7.8)2.1%💥 ExploitNessus Vulnerability Scanner30/7/200716/6/2026
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability.
ModificadaAlta (9.3)11%💥 ExploitNessus Vulnerability Scanner30/7/200716/6/2026
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the saveNessusRC method, which writes text specified by the addsetConfig method, possibly related to the…
ModificadaAlta (7.8)5.7%💥 ExploitNessus Vulnerability Scanner27/7/200716/6/2026
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll.
ModificadaAlta (7.8)2.1%—Amavis Virus ScannerGentoo File13/4/200716/6/2026
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
ModificadaBaja (1.9)1.8%💥 ExploitAcunetix WEB Vulnerability Scanner9/1/200716/6/2026
Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-Length values.
ModificadaAlta (10)7.4%—Softwin BitdefenderSoftwin Bitdefender AntivirusSoftwin Bitdefender Internet SecuritySoftwin Bitdefender Mail Protection+118/12/200616/6/2026
Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to…
ModificadaAlta (10)1.4%—Paisterist Simple Http Scanner27/9/200616/6/2026
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.3 have unknown impact and attack vectors.
ModificadaAlta (10)1.4%—Paisterist Simple Http Scanner27/9/200616/6/2026
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.2 have unknown impact and attack vectors.
ModificadaCrítica (9.8)1.8%—Paisterist Simple Http Scanner27/9/200616/6/2026
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.4 have unknown impact and attack vectors.
ModificadaAlta (7.5)1.3%—Mailscanner2/11/200516/6/2026
SQL injection vulnerability in in the authenticate function in MailWatch for MailScanner 1.0.2 allows remote attackers to execute arbitrary SQL commands.
ModificadaMedia (5)1.7%—Mailwatch FOR MailscannerAI2/11/200516/6/2026
Directory traversal vulnerability in the ruleset view for MailWatch for MailScanner 1.0.2 allows remote attackers to access arbitrary files.
ModificadaAlta (7.5)1.4%—Mailscanner24/5/200516/6/2026
Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers to bypass virus detection.
ModificadaMedia (4.6)0.42%—GFI Languard Network Security Scanner2/5/200516/6/2026
lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.
ModificadaMedia (5)1.6%—F-secure Anti-virusF-secure Content Scanner ServerF-secure Internet Gatekeeper9/9/200416/6/2026
The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (service crash due to unhandled exception) via a certain…
ModificadaMedia (6.4)1.1%—Mailscanner31/12/200216/6/2026
MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner.
ModificadaAlta (7.5)2.3%—Virgil CGI Scanner31/12/200216/6/2026
Virgil CGI Scanner 0.9 allows remote attackers to execute arbitrary commands via the (1) tar (TARGET) or (2) zielport (ZIELPORT) parameters.
Orbitaley — Vulnerabilidades